Miasma Malware Abuses npm Packages and GitHub Actions in Stealthy Supply Chain Attack
Security researchers have uncovered a new supply chain attack involving malware called Miasma, which targets developers by abusing npm packages and GitHub Actions workflows. Instead of attacking users directly, the campaign focuses on software development environments where malicious code can spread through trusted projects. Researchers say this approach allows attackers to compromise systems before applications … Continued