TL;DR The Shai-Hulud Miasma campaign has a fresh series of malicious packages following the compromise of the czirker maintainer account, affecting both the RStreams and Leo Platform ecosystems. Sonatype is implica ting 23 malicious package versions with this campaign. This wave builds directly on the Miasma playbook Sonatype recently reported : m oving beyond obvious preinstall and postinstall scripts to abuse binding.gyp, steal credentials, validate access, and propagate through trusted package publishing workflows.
Miasma Returns: Leo Platform Compromise in npm
calendar_today
June 25, 2026
person
research@sonatype.com (Sonatype Security Research Team)
domain
sonatype