In the first week of June 2026, a variant of the Shai-Hulud worm called Miasma worked its way through npm, PyPI and Microsoft's GitHub organisations. It began on 1 June 2026, when a compromised Red Hat employee's GitHub account pushed malicious commits to RedHatInsights repositories and the projects' own release workflows published backdoored @redhat-cloud-services packages. Within days a second npm wave followed, 73 Microsoft repositories were seeded and disabled, and a PyPI wave branded "Hades" planted startup hooks in Python wheels. Every wave had the same goal: steal publishing tokens, CI secrets and cloud credentials, then use them to infect more projects. Miasma and Hades show how a single developer identity, once stolen, turns trusted pipelines and AI coding tools into a distribution channel for credential theft.
Key takeaways
- Wiz says malicious commits were pushed to two RedHatInsights repositories on 1 June 2026 at 10:53 and 13:44 UTC from a compromised Red Hat employee's GitHub account, and GitHub Actions OIDC then published the packages with valid provenance.
- Counts vary: Wiz reported at least 32 package releases, Cybersecurity Dive reported 32 packages and 96 versions. A second npm wave on 3 June hit 57 packages and 286+ versions, according to StepSecurity.
- On 5 June a re-compromised contributor account pushed trigger files for Claude Code, Gemini CLI, Cursor and VS Code into Azure/durabletask. GitHub disabled 73 Microsoft repositories in 105 seconds, according to BleepingComputer.
- Socket found the Hades wave on 7 June: 37 malicious wheels across 19 PyPI packages, executed through Python .pth startup files and exfiltrating to repositories marked "Hades - The End for the Damned".
- Lesson: provenance proves the build path, not the intent of whoever controls the account. Developer accounts, OIDC publishing, CI secrets and AI tool configuration all need to be governed as identities.
At a glance
| Organisation(s) | Red Hat (@redhat-cloud-services npm packages); other npm maintainers including @vapi-ai; Microsoft's GitHub organisations; PyPI projects including dynamo-release and coolbox; developers and CI systems that installed affected versions |
|---|---|
| When | 1 June 2026 (Red Hat wave) to 7 June 2026 (Hades PyPI wave); related durabletask PyPI compromise in May 2026 |
| Attacker | Unattributed. Wiz says the payload appears derived from the Mini Shai-Hulud malware open-sourced by TeamPCP; Socket did not attribute the Hades wave to a specific actor |
| Entry point | A compromised Red Hat employee GitHub account; later, stolen npm and PyPI publishing tokens and a re-compromised contributor account on Azure/durabletask |
| Identities abused | Developer GitHub accounts, GitHub Actions OIDC trusted publishing, npm and PyPI publishing tokens, GitHub tokens and Actions secrets, AWS, GCP and Azure credentials, Kubernetes and Vault tokens, SSH keys, AI coding tool configuration |
| Impact | Hundreds of malicious npm and PyPI artifacts (Socket counts 448 across the campaign); 73 Microsoft repositories disabled; Azure/functions-action outage for developer workflows |
| Category | NHI (publishing tokens, CI and cloud secrets), software supply chain, AI coding agents as execution vectors |
What happened
The Red Hat wave came first. Wiz Research says it identified the compromise on 1 June 2026, with malicious commits pushed in two waves that day, at 10:53 UTC and 13:44 UTC. A compromised Red Hat employee GitHub account pushed "malicious orphan commits to two RedHatInsights repositories, bypassing code review." The repositories' GitHub Actions workflows requested OIDC tokens for npm publishing and released the packages with valid SLSA provenance, so they looked like normal releases.
A preinstall script ran an obfuscated index.js. Wiz says this variant added "collectors for GCP and Azure identities" and generated "a uniquely encrypted payload for each infection." It also created public GitHub repositories with the description "Miasma: The Spreading Blight", hence the name. Wiz says "The payload appears to be derived from the (Mini) Shai-Hulud malware open-sourced by TeamPCP," with changes that are "largely cosmetic," as quoted by DevOps.com.
How the employee account was taken over has not been confirmed. The Hacker News reported that Whiteintel "detected a Red Hat GitHub credential and session cookie in infostealer logs on April 13 and May 15, 2026", and that OX Security found the first commit with the Miasma string on 29 May 2026. Red Hat said it was "aware of security reports regarding certain npm packages within our development tooling ecosystem" and had "not identified any impact to customer or partner environments or Red Hat production systems," according to Cybersecurity Dive.
The second npm wave began at 23:30 UTC on 3 June, according to StepSecurity. In under two hours it compromised 57 packages and more than 286 malicious versions, including @vapi-ai/server-sdk with more than 408,000 monthly downloads. The attacker dropped the preinstall hook and instead used a 157-byte binding.gyp file, which StepSecurity calls "Phantom Gyp". When npm builds a native module, gyp's command substitution runs node index.js, "bypassing most install-script security checks entirely."
On 5 June the worm reached Microsoft. BleepingComputer reported that the durabletask repository had been compromised in May, when malicious durabletask versions 1.4.1 to 1.4.3 were pushed to PyPI, and that incomplete cleanup let the attackers return. The Hacker News said the new commit came from "what appeared to be the same contributor account" and added a 4.3 MB payload runner plus five trigger files for Claude Code, Gemini CLI, Cursor, VS Code and the npm test script. These run code when a developer opens the repository in an AI coding tool or IDE, with no package install needed. GitHub disabled 73 repositories across the Azure, Azure-Samples, microsoft and MicrosoftDocs organisations within 105 seconds, including Azure/functions-action, which broke deployment workflows for developers who depended on it.
Two days later, on 7 June, Socket detected the Hades wave on PyPI: 37 malicious wheels across 19 packages, including bioinformatics tools such as dynamo-release and coolbox. Instead of an install script, the wheels ship a Python .pth startup file, which the interpreter runs whenever Python starts. The payload targets GitHub tokens, npm and PyPI credentials, cloud keys, Kubernetes tokens, SSH keys, Docker configuration, shell histories and "Claude/MCP configs", and exfiltrates to GitHub repositories marked "Hades - The End for the Damned".
Timeline
| Date | Event |
|---|---|
| 13 April and 15 May 2026 | Whiteintel sees a Red Hat GitHub credential and session cookie in infostealer logs, as reported by The Hacker News. |
| May 2026 | TeamPCP publicly releases the Mini Shai-Hulud worm; malicious durabletask 1.4.1 to 1.4.3 pushed to PyPI. |
| 29 May 2026 | First commit containing the "Miasma: The Spreading Blight" string appears, according to OX Security. |
| 1 June 2026, 10:53 and 13:44 UTC | Malicious commits pushed to two RedHatInsights repositories; @redhat-cloud-services packages published through OIDC with provenance (Wiz). |
| 2 June 2026 | Red Hat confirms it is investigating; affected packages removed from npm. |
| 3 June 2026, 23:30 UTC | Second npm wave starts using binding.gyp; 57 packages and 286+ versions compromised in under two hours (StepSecurity). |
| 5 June 2026 | Trigger files for AI coding tools pushed to Azure/durabletask; GitHub disables 73 Microsoft repositories within 105 seconds. |
| 7 June 2026 | Socket detects the Hades PyPI wave: 37 wheels across 19 packages using .pth startup hooks. |
| 9 June 2026 | BleepingComputer reports the Microsoft repositories restored; Microsoft says it notified a small number of customers. |
How it happened: the identity attack path
- A developer identity taken over. A Red Hat employee's GitHub account was used to push commits that bypassed code review. Its credentials had surfaced in infostealer logs weeks earlier, according to Whiteintel, although the exact route has not been confirmed.
- A trusted pipeline did the publishing. The repositories' GitHub Actions workflows obtained OIDC tokens and published to npm with valid SLSA provenance. No long-lived npm token had to be stolen for the first releases.
- Secrets harvested where code runs. Preinstall scripts, binding.gyp builds and Python .pth files each ran automatically on developer machines and CI runners, collecting publishing tokens, GitHub Actions secrets, cloud credentials, Kubernetes and Vault tokens and SSH keys.
- Stolen tokens became new entry points. The payload collects npm and PyPI publishing tokens alongside everything else. StepSecurity describes the second npm wave as a cross-ecosystem worm able to infect npm, RubyGems and GitHub repositories with forged Sigstore provenance, so each compromised machine can become a new spreader.
- Old access left open. The Azure/durabletask contributor account compromised in May was used again in June. StepSecurity's Ashish Kurmi told The Hacker News the attacker may have kept working credentials from May, the victim may have been re-infected, or another contributor's token may have been abused.
- AI coding tools used as launchers. Trigger files in .claude, .gemini, .cursor and .vscode folders run the payload when a repository is opened, turning agent and editor configuration into an execution path that sits outside package manifests and lockfiles.
Impact
Figures differ by source and by wave. For the Red Hat wave, Wiz reported at least 32 package releases averaging about 80,000 weekly downloads; Cybersecurity Dive reported 32 packages and 96 versions, while The Hacker News listed seven packages. For the second npm wave, StepSecurity counted 57 packages and more than 286 malicious versions. For Hades, Socket counted 37 wheels across 19 packages and 448 malicious artifacts across the npm and PyPI campaign as a whole.
On GitHub, 73 Microsoft repositories were disabled. Microsoft said it "notified a small number of customers who may have pulled down content from the affected repositories," according to BleepingComputer, and the repositories were later restored.
The larger impact is on credentials. Cybersecurity Dive advised that anyone who downloaded affected versions should assume CI secrets, cloud credentials, SSH keys and npm tokens are compromised.
What this means for NHI governance
Miasma and Hades are non-human identity attacks at every step. The first releases were published by a CI workflow using OIDC, after a human developer account was hijacked. Every later wave depended on publishing tokens, GitHub tokens and cloud keys stolen from machines and build runners.
Three lessons stand out. First, provenance and trusted publishing attest that a package came from a given workflow, not that the identity driving the workflow was legitimate. Second, incomplete revocation is a real risk: the durabletask contributor account appears to have been used twice, a month apart. Rotation and clean-up after a compromise need to cover every token, session and account the attacker could reach. Third, AI coding agents and IDEs now read configuration that can run code, so a cloned repository can act on a developer's credentials before any package is installed.
The campaign sits between the Shai-Hulud campaign it descends from and the later ChainDrop npm worm, which used the same pattern of maintainer takeover and token reuse.
Recommendations
- Treat affected hosts as compromised. Remove persistence from .claude, .gemini, .cursor and .vscode folders and Python .pth files, then rotate every npm, PyPI, GitHub, cloud, Kubernetes, Vault and SSH credential the host or runner could reach.
- Close old access completely. After any account compromise, revoke all sessions, tokens and OAuth grants for that identity, not just the password, and confirm that no stale contributor access remains.
- Protect release workflows. Require review for commits to release branches, block orphan commits and force pushes, and gate OIDC publishing jobs behind approval. The CI/CD Pipeline Identity Security Guide covers these controls.
- Minimise secrets in build jobs. Give each job only the credentials it needs, prefer short-lived federated credentials and keep long-lived keys in a vault, following the Secrets Management Guide.
- Restrict code that runs on install and on open. Disable npm lifecycle scripts and native builds where they are not needed, delay adoption of new releases, and review AI coding tool and editor settings in cloned repositories before trusting them. See the AI Coding Agents Security Guide.
- Inventory publishing identities. Know which people, tokens and workflows can publish each package you own, and remove any that are not needed.
Frequently asked questions
What are the Miasma and Hades worms?
They are self-propagating credential stealers seen in June 2026 and derived from the Mini Shai-Hulud malware that TeamPCP released publicly. Miasma hit npm packages and GitHub repositories, including 73 Microsoft repositories, and Hades was a PyPI wave that used Python .pth startup files.
How did Miasma get into Red Hat's npm packages?
According to Wiz, a compromised Red Hat employee GitHub account pushed malicious orphan commits to two RedHatInsights repositories, and the projects' GitHub Actions workflows then published the packages to npm through OIDC with valid provenance.
Was Microsoft Azure affected by the Miasma worm?
Microsoft's GitHub repositories were affected, not Azure cloud services. On 5 June 2026 GitHub disabled 73 repositories across the Azure, Azure-Samples, microsoft and MicrosoftDocs organisations after malicious files were pushed to Azure/durabletask. Microsoft said it notified a small number of customers who may have pulled down content, and the repositories were later restored.
Related NHI Mgmt Group resources
ChainDrop npm worm · Shai-Hulud npm campaign · Mastra npm supply chain attack · CI/CD pipeline exploitation · NHI breaches
How NHI Mgmt Group can help
Worms like Miasma and Hades feed on publishing tokens, CI secrets, cloud keys and AI tool credentials that nobody has fully inventoried or governed. Our NHI Foundation Level Training Course gives teams the practical grounding to find, govern and protect these non-human identities.
References
- Wiz: Miasma, Supply Chain Attack Targeting RedHat npm Packages (1 June 2026)
- The Hacker News: Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm (1 June 2026)
- Cybersecurity Dive: Dozens of Red Hat npm packages targeted in supply chain attack (2 June 2026)
- DevOps.com: Shai-Hulud Clone 'Miasma' Compromises 32 Red Hat npm Packages (2 June 2026)
- StepSecurity: Miasma npm Supply Chain Attack, Self-Spreading Worm via Phantom Gyp (3 June 2026)
- The Hacker News: Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack (6 June 2026)
- Socket: Shai-Hulud Descends to Hades, Miasma Worm Campaign Spreads with New PyPI Wave (7 June 2026)
- BleepingComputer: GitHub disables Microsoft repos pushing password-stealing malware (9 June 2026)