Skip to main content
← Back to Demos
SBOM intermediate · 15 min

SBOM Analysis Surfaces Malicious npm Package in App Dependencies

The Miasma supply chain attack compromised official Red Hat npm packages, with the Shai-Hulud threat group injecting malicious code into otherwise legitimate packages to deploy a credential-stealing worm. Once installed, the worm harvested GitHub tokens, cloud provider credentials, and environment variables, then spread autonomously through the dependency chain. Detecting such implants inside a sprawling dependency tree is exactly what SBOM analysis is built for. This demo uses a synthetic application manifest whose dependency list includes a package flagged as malicious, alongside benign metadata — nothing real is downloaded. The SBOM module cross-references every dependency against threat intelligence, pinpoints the poisoned package and its version, and reports the exposure path, so security teams can block the release before the compromised component ships.

Attack Technique

Malicious package in dependency tree

MITRE ATT&CK

T1195.002 ↗

Platforms

linux

File Types

.json

MetaDefender Capabilities

SBOM

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---