Signal

Miasma malware poisons npm packages while Photo ZIP phishing targets hospitality with Node.js implant

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-06-25 22:30 UTCUpdated 2026-06-26 12:18 UTC
rss
cveexploitsmalwarethreat_actorsincident_responsesupply_chain
Trend in the last 24h
Current brief openSource links open
This current signal is open on the public brief with summary, metadata, source links, and full evidence. Pro adds compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.
3 top sources shown
The Register Security
theregister.com · theregister.com · 2026-06-26 12:18 UTC
Microsoft Security Blog
microsoft.com · microsoft.com · 2026-06-25 22:30 UTC
Overview

Coverage centers on: Microsoft Security Blog.

Entities
MicrosoftLeo PlatformRStreams
Score total
1.35
Momentum 24h
4
Posts
4
Origins
3
Source types
1
Duplicate ratio
0%
Why now
  • Miasma's rapid automated poisoning of npm packages shows increasing sophistication and speed in supply chain attacks.
  • The ongoing Photo ZIP campaign has been active since April 2026, indicating persistent targeting of hospitality organizations.
  • Both campaigns demonstrate evolving tactics that require heightened vigilance and updated defenses in affected sectors.
Why it matters
  • Supply chain attacks like Miasma threaten software ecosystems by injecting malicious code into widely used packages.
  • Phishing campaigns targeting hospitality with persistent implants risk operational disruption and data theft in critical service sectors.
  • Credential theft from developer and cloud environments can lead to broader network compromises and further malware propagation.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • Miasma malware campaign poisoned over 20 npm packages by compromising a maintainer account and distributing malicious updates.
  • Miasma malware steals cloud credentials, GitHub tokens, Kubernetes secrets, and developer credentials from infected workstations and CI runners.
  • Photo ZIP phishing campaign targets hospitality industry with Node.js implant using obfuscated PowerShell and registry persistence for long-term access.
How sources frame it
  • Microsoft Threat Intelligence: neutral
All evidence
All evidence
Microsoft Security Blog
microsoft.com · microsoft.com · 2026-06-25 22:30 UTC
The Register Security
theregister.com · theregister.com · 2026-06-26 12:18 UTC
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
thehackernews · thehackernews.com · 2026-06-26 11:05 UTC
Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant
thehackernews · thehackernews.com · 2026-06-26 09:27 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 4 / 0
Top publishers (this list)
  • thehackernews (2)
  • microsoft.com (1)
  • theregister.com (1)
Top origin domains (this list)
  • thehackernews.com (2)
  • microsoft.com (1)
  • theregister.com (1)