Miasma npm Worm Hits LeoPlatform Packages

Date Observed: June 24, 2026 (LeoPlatform wave); follow-on @immobiliarelabs wave June 26, 2026Ecosystem: npm (primary); propagation logic also targets PyPI, RubyGems, and GoTargets: LeoPlatform / RStreams maintainer account (czirker); ~20 leo-* and rstreams-* packages, plus later @immobiliarelabs Backstage pluginsAttack Type: Self-propagating supply chain worm delivered through a build-time binding.gyp install hook (Mini Shai-Hulud / Miasma […]
The Executive Guide to SBOM Security

By David Pulaski, CXO & Co-Founder, InvisiRiskPublished June 2026 TL;DR A Software Bill of Materials (SBOM) is a complete inventory of every component inside a piece of software. SBOM security is the practice of producing, validating, and acting on that inventory to manage software supply chain risk. For executives, an SBOM matters because it is […]
Inside the Mastra npm Supply Chain Attack

Date Observed: June 17, 2026Ecosystem: npm (@mastra scope)Targets: Developer workstations and CI/CD runners installing @mastra/* packagesAttack Type: Account takeover + dependency injection + typosquatting + credential-stealing RATImpact: Over 140 packages trojanized; ~8M weekly downloads exposed; cryptocurrency wallet and credential theft Key Takeaways A Mastra contributor’s npm account was hijacked after scope permissions were never revoked, […]
Healthcare Software Supply Chain Security Explained

By David Pulaski, CXO & Co-Founder, InvisiRiskPublished June 2026 TL;DR Healthcare software is assembled from open-source packages, third-party code, and automated CI/CD pipelines, and most of the security tools protecting it look at code before the build or the running application after it. The build itself, where dependencies execute, secrets are live, and network connections […]