SBOM Analysis Surfaces Malicious npm Package in App Dependencies
The Miasma supply chain attack compromised official Red Hat npm packages, with the Shai-Hulud threat group injecting malicious code into otherwise legitimate packages to deploy a credential-stealing worm. Once installed, the worm harvested GitHub tokens, cloud provider credentials, and environment variables, then spread autonomously through the dependency chain. Detecting such implants inside a sprawling dependency tree is exactly what SBOM analysis is built for. This demo uses a synthetic application manifest whose dependency list includes a package flagged as malicious, alongside benign metadata — nothing real is downloaded. The SBOM module cross-references every dependency against threat intelligence, pinpoints the poisoned package and its version, and reports the exposure path, so security teams can block the release before the compromised component ships.
Attack Technique
Malicious package in dependency tree
MITRE ATT&CK
T1195.002 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗