04 Jun 2026
Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp
self-replicating worm is spreading across the npm registry using binding.gyp, a file that triggers code execution during npm install without touching package.json scripts. The attack bypasses conventional security tools and has already compromised dozens of packages across multiple maintainer accounts.
Sai Likhith
2026