Miasma campaign targets npm ecosystem, compromising AI packages
The Miasma supply chain campaign, which previously compromised 32 Red Hat packages, is now targeting the npm ecosystem in a new wave of attacks. This campaign specifically targets high-traffic AI packages, including vapi-ai/server-sdk with 71,000 weekly downloads and ai-sdk-ollama with 31,000 weekly downloads.
Supply chain attacks are increasingly targeting the rapidly growing AI developer ecosystem to maximize their blast radius.
- –Miasma's pivot from Red Hat packages to the npm ecosystem demonstrates the campaign's persistence and adaptability.
- –The specific targeting of high-download AI tools indicates attackers are strategically following current developer trends to compromise as many systems as possible.
- –The focus on AI SDKs highlights the critical need for robust dependency verification in modern AI development workflows.
DISCOVERED
58d ago
2026-06-04
PUBLISHED
58d ago
2026-06-04
RELEVANCE
AUTHOR
AikidoSecurity