Affected Systems
npm packages LeoPlatform and RStreams compromised by Miasma malware family. Attack extends to GitHub Actions workflows and Go ecosystem. Organizations using these packages or dependent projects are affected.
Exploitation Status
Active supply chain attack confirmed. Malicious packages published to npm registry. GitHub Actions workflows actively abused. Exploitation is ongoing in the wild.
Business Impact
Organizations using compromised npm packages may have malware deployed in production environments. Build pipelines using GitHub Actions could be compromised. Potential for credential theft, code execution, and lateral movement. No CVE assigned yet, indicating early detection phase. Immediate inventory and containment required.
Urgency
🔴 Immediate
Recommended Actions
- Immediately audit all projects for dependencies on LeoPlatform and RStreams npm packages and remove if present
- Review GitHub Actions workflow logs for unauthorized modifications or suspicious activity in the past 90 days
- Scan build environments and CI/CD pipelines for indicators of compromise related to Miasma malware
- Rotate credentials and secrets accessible to affected build systems and GitHub Actions runners
- Monitor npm package-lock.json and Go module files for unexpected changes to LeoPlatform, RStreams, or related dependencies
