
Miasma npm Worm Hits LeoPlatform Packages
Date Observed: June 24, 2026 (LeoPlatform wave); follow-on @immobiliarelabs wave June 26, 2026Ecosystem: npm (primary); propagation logic also targets PyPI,

Date Observed: June 24, 2026 (LeoPlatform wave); follow-on @immobiliarelabs wave June 26, 2026Ecosystem: npm (primary); propagation logic also targets PyPI,

Date Observed: June 17, 2026Ecosystem: npm (@mastra scope)Targets: Developer workstations and CI/CD runners installing @mastra/* packagesAttack Type: Account takeover +

Date Observed: June 1, 2026Ecosystem: npm @redhat-cloud-services Targets: CI/CD pipelines and developer workstations consuming @redhat-cloud-services packages Attack Type: CI/CD pipeline compromise; preinstall

Date Observed: May 19, 2026Ecosystem: PyPI (Python)Targets: CI/CD runners, cloud workloads, Kubernetes clusters, developer environments consuming durabletaskAttack Type: Supply chain

Date Observed: May 19, 2026Ecosystem: npm (Node.js)Targets: @antV data visualization packages, echarts-for-react, timeago.js, size-sensor, canvas-nest.js, CI/CD pipelines, developer workstations.Attack Type:

Date Observed: May 11, 2026Ecosystem: npm, PyPITargets: Developers using @tanstack/react-router and related packages; UiPath, Mistral AI, OpenSearch, and Guardrails AI

Date Observed: Late April 2026Ecosystem: RubyGems and Go ModulesTargets: Developers, CI runners, and GitHub Actions pipelinesAttack Type: Malicious package campaign,

Date Observed: April 29–30, 2026Ecosystem: npm, PyPI, Packagist (PHP)Targets: SAP enterprise developers, AI/ML engineers, DevOps and DevSecOps teams using Intercom

Date Observed: April 23, 2026 Ecosystem: npm (Node.js) Targets: Developer workstations, GitHub Actions CI/CD pipelines, cloud environments, AI coding tool

Date Observed: April 22, 2026Ecosystem: PyPI (Python)Targets: AI/MLOps teams, CI/CD pipelines, cloud-connected LLM inference environmentsAttack Type: Supply chain compromiseImpact: SSH