EarlyTerms

Miasma (worm)

Emergent · Emerged · 9 days old · Last reviewed

Miasma is a self-propagating supply-chain worm that steals developer credentials and cloud secrets by hijacking npm packages, PyPI packages, and GitHub repository configuration files. Built on the publicly released Mini Shai-Hulud codebase open-sourced by threat group TeamPCP on May 12, 2026, Miasma adds new attack vectors targeting AI coding agents.

The campaign opened June 1, 2026, compromising 32 @redhat-cloud-services npm packages (80,000 weekly downloads) via hijacked CI/CD credentials. A June 3 wave introduced "Phantom Gyp" to evade install-hook scanners. By June 5, GitHub disabled 73 Microsoft repositories — including the Azure Functions GitHub Action — after Miasma planted configuration hooks that fire when a developer opens the repo in Claude Code, Gemini CLI, Cursor, or VS Code.

💡

On June 5, 2026, a malicious commit to Azure/durabletask planted five files: `.claude/settings.json` hooking Claude Code's SessionStart, `.gemini/settings.json` for Gemini CLI, `.cursor/rules/setup.mdc` using prompt injection, `.vscode/tasks.json` triggering on folder open, and `.github/setup.js` — a 4.6 MB obfuscated JavaScript payload that harvests AWS, Azure, GCP, Kubernetes, and 90+ developer tool credentials before self-propagating to any accessible repository.

Think of it as a hotel door-propping attack: one compromised key card lets the worm walk into every room on the floor.

Search Interest Placeholder

GTrends data pending — run make et-enrich-trends.
Term Lifecycle
  1. Nascent
    0–7 days
  2. Emergent ← now
    8–30 days
  3. Validating
    31–90 days
  4. Rising
    91–180 days
  5. Established
    180 days +

Why is it emerging now?

TL;DR

Miasma is the first worm to weaponize AI coding agent config files for persistence. Its June 1–5 waves hit Red Hat (32 npm packages) then Microsoft (73 GitHub repos including Azure Functions Action). With Mini Shai-Hulud open-sourced May 12, any threat actor can now clone and deploy this capability.

6 forces driving coverage — scroll →

Outlook

6-month signal projection and commercial timeline.

Signal high
Revenue strong

AI coding agent config files are a new attack surface; every team using Claude Code or Cursor needs a mitigation playbook within weeks.

Risk · If Microsoft and Red Hat revoke all stolen tokens, the campaign's spread mechanism collapses fast.

Analogs · XZ Utils backdoor · SolarWinds supply chain · event-stream malware

Monetization timeline
  1. now
    Security briefings in demand

    Teams scrambling to audit repos for injected config files; incident-response and tooling guidance commands premium.

  2. 3-6mo
    AI agent hardening tools

    Vendors build scanning products to detect malicious .claude/settings.json and .cursor/rules injections before developers open repos.

  3. 6-12mo
    Policy and compliance layer

    Enterprise AI coding agent governance frameworks emerge; compliance auditors add AI-agent config to supply chain review checklists.

Competition & Opportunity for term “Miasma (worm)”

Three heuristic signals derived from the tracked queries, the term's monetization cards, and its cluster neighbors. Directional, not audited.

Content Gap
10 queries tracked
Led by General (8), Explainer (1)
10 Suggest-only tails — long-tail opening
Revenue Potential
10% commercial-intent queries
2 monetization angles mapped
Mostly informational — pre-commercial
Build Difficulty
Medium
Stage: emergent — early enough to land
8 / 13 default TLDs taken · oldest incumbent miasma.com (1998-07-03)
9 related terms already published
Heuristic · signals: tracked queries, term monetization cards, cluster neighbors

Ideas for term “Miasma (worm)”

Buildable pitches — turn this term into an article, site, product, post, newsletter, video, or course. Steal any card and run with it.

Article
What is the Miasma worm and how does it target AI coding agents?

High-intent explainer for the 'miasma worm' and 'miasma supply chain attack' queries; zero competition from pre-existing pages — this term is brand-new.

Article
How to audit your repository for Miasma worm configuration injections (Claude Code, Cursor, VS Code)

Practical checklist article targeting developers asking how to verify their repos are clean; step-by-step detection of .claude/settings.json, binding.gyp payloads.

Article
Miasma vs XZ Utils vs SolarWinds: how AI-agent supply chain attacks differ from traditional vectors

Comparative explainer for security professionals evaluating risk frameworks; angles on why config-file injection evades SLSA provenance checks.

Product
CI/CD pre-commit scanner for AI coding agent config file injection

A lightweight GitHub Action or pre-commit hook that flags unexpected .claude/, .gemini/, or .cursor/rules/ changes; directly fills the gap Miasma exposed.

Product
Repository audit dashboard for Miasma-style worm indicators

SaaS tool that scans GitHub org repos for Phantom Gyp patterns, rogue binding.gyp files, and AI agent session hooks — SOC team audience.

Newsletter
Supply Chain Security Weekly — AI agent attack surface edition

Recurring briefing tracking npm/PyPI/GitHub worm campaigns for platform-engineering and AppSec teams; Miasma is the hook for launch issue.

Video
Live demo: How the Miasma worm uses your .claude/settings.json to steal AWS keys in under 5 seconds

Technical YouTube walkthrough with a sandboxed reproduction; exploits the visceral 'it happens on clone' angle for security YouTube audience.

Post HN / r/netsec / r/programming
AI Coding Agents Are Now Supply Chain Attack Surfaces — Here's the Proof

The Miasma worm didn't exploit a zero-day. It put a file in .claude/settings.json and waited for you to open the repo.

Post LinkedIn / DevSecOps community
73 Microsoft Repos Just Got Taken Down Because Someone Never Rotated Their GitHub Token

The Azure Functions GitHub Action was disabled for 30+ minutes on June 5 because a credential stolen on May 19 was still valid 17 days later.

Post Newsletter / YouTube / Tech media
The Worm That Learned to Live Inside Claude Code

Mini Shai-Hulud source code went public on GitHub on May 12, 2026 — and within 20 days a new variant called Miasma had compromised Red Hat, then Microsoft.

What People Search

Long-tail queries from Google Suggest + Trends. Volume and competition are heuristics — directional, not audited. Content Type comes from query shape.

Keyword
Competition
Content Type
miasma
Very Low
General
miasma meaning
Very Low
Explainer
miasma theory
Very Low
General
miasma chronicles
Very Low
General
miasmatic theory
Very Low
General
miasma necromancer
Very Low
General
miasma zzz
Very Low
General
miasmata
Very Low
General
1–8 of 10
1 / 2
Updated — · sources: Google Trends, Google Suggest · Competition is heuristic

SERP of term “Miasma (worm)”

What searchers see today — organic results on top, paid ads if anyone's bidding. Ad density is a real-time commercial signal.

FAQ

What is Miasma (worm)?

Miasma is a self-propagating supply-chain worm that steals developer credentials and cloud secrets by hijacking npm packages, PyPI packages, and GitHub repository configuration files.

Why is Miasma (worm) emerging now?

Miasma is the first worm to weaponize AI coding agent config files for persistence. Its June 1–5 waves hit Red Hat (32 npm packages) then Microsoft (73 GitHub repos including Azure Functions Action). With Mini Shai-Hulud open-sourced May 12, any threat actor can now clone and deploy this capability.

When did Miasma (worm) emerge?

Publicly emerged around 2026-06-01 (about 9 days ago as of 2026-06-10). EarlyTerms first recorded a pipeline signal on 2026-06-09.

Related Terms

Other terms in the same space — aliases, subtypes, competitors, and neighbors to explore next.

Explore next
Also mentioned
  • Part of supply chain attack·Mini Shai-Hulud
  • Includes Phantom Gyp

Sources

Primary URLs this report cites — open any to verify the claim yourself.

  1. 01 Snyk: Miasma supply chain attack — malicious code in RedHat-cloud-services npm (Jun 1, 2026) snyk.io
  2. 02 StepSecurity: Miasma Worm Hits Microsoft — Azure Functions Action and 72 Other Repos Disabled (Jun 8, 2026) stepsecurity.io
  3. 03 StepSecurity: Miasma npm Supply Chain Attack — Phantom Gyp self-spreading worm (Jun 4, 2026) stepsecurity.io
  4. 04 SafeDep: Miasma Worm Targets AI Coding Agents via GitHub Repo Config Injection (Jun 5, 2026) safedep.io
  5. 05 Microsoft Security Blog: Preinstall to Persistence — Inside the Red Hat npm Miasma Campaign (Jun 2, 2026) microsoft.com
  6. 06 Wiz Research: Miasma Supply Chain Attack Targeting RedHat npm Packages (Jun 2, 2026) wiz.io
  7. 07 Snyk Vulnerability DB: SNYK-JS-REDHATCLOUDSERVICESHCCFEOMCP-17117403 — Critical 9.3 CVSS (Jun 1, 2026) security.snyk.io
  8. 08 SafeDep Threat Intelligence: Miasma — The Spreading Blight campaign tracker (ongoing) safedep.io