Miasma Worm Spread Through Poisoned Developer Packages
The Miasma worm campaign compromised 73 Microsoft-owned GitHub repositories, using a novel technique dubbed Phantom Gyp to exfiltrate credentials and propagate through six-stage infection chains that target developer environments; a Rust-based variant called IronWorm simultaneously hit the npm ecosystem. Such worms hide inside package archives and CI artifacts, executing on install and stealing tokens without raising a single alert. Detecting them demands deep inspection of the package itself, not just the filename. This demo runs the EICAR test file — the standard, completely safe detection sample — packed inside a zip archive, mimicking the delivery shape of a poisoned package. Metascan scans the archive and its contents with 30+ anti-malware engines, detects the embedded threat, and exposes it before it can reach a build pipeline or developer workstation.
Attack Technique
Worm spread via npm packages
MITRE ATT&CK
T1195.002 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗