SlowMist: New npm malware variant spreads, affecting 23 packages and impacting 408 GitHub repositories
SlowMist released threat intelligence stating that new npm malware variants—Shai-Hulud, Miasma, and Hades—linked to the compromised npm developer account “czirker” are impacting the npm ecosystem. This campaign triggers during `npm install` execution via a preconfigured `binding.gyp` file. It has been confirmed to affect 23 packages, including `leo-logger`, which sees approximately 3,140 weekly downloads. As of the report’s publication, 408 GitHub repositories have been found infected due to stolen credentials.