Leo Platform npm Miasma / Phantom Gyp Compromise

Confirmed
Discovered Jun 25, 2026

StepSecurity disclosed a June 24, 2026 Leo Platform npm supply-chain compromise affecting 20 packages published in a three-second burst. Socket and Sonatype then tied three more malicious npm packages to the same Miasma / Mini Shai-Hulud Phantom Gyp tradecraft, extending the incident into a 23-package campaign update.

10
Affected Packages
18
Observables
6
Sources

Timeline

1 of 1 rows

Timeline
DateEventDescriptionSource
Jun 25, 2026Fresh source reviewReviewed direct and primary sources for the last-two-weeks supply-chain refresh; this preview intentionally excludes older Halting Problems article data.Direct source

Affected Software

10 of 10 rows

Affected Software
PackageEcosystemVersion RangeStatusConfidenceSource
leo-loggernpm1.0.8Malicious90%StepSecurity
leo-sdknpm6.0.19Malicious90%StepSecurity
leo-awsnpm2.0.4Malicious90%StepSecurity
leo-confignpm1.1.1Malicious90%StepSecurity
leo-streamsnpm2.0.1Malicious90%StepSecurity
serverless-leonpm3.0.14Malicious90%StepSecurity
leo-connector-mongonpm3.0.8Malicious90%StepSecurity
serverless-conventionnpm2.0.4Malicious90%StepSecurity
rstreams-metricsnpm2.0.2Malicious90%StepSecurity
leo-connector-elasticsearchnpm2.0.6Malicious90%StepSecurity

IOC Clipboard

18 IOCs
domainapi.github.com
domaingithub.com
urlhttps://api.github.com/graphql
urlhttps://github.com/oven-sh/bun/releases/download/bun-v1.3.13/
hashd45ad3cffbcc7c4b354ebe9d71d002fa585379ec
hash1dcc0a39e1cd7293a9058cfc41e1afe8b397c943
hashef8bf6dd92cbc29ef8d23f3f0fa786ed20a856b1
hash9be49287057cd6a54ef4a70a8d541a7259efbd2d
hashc05068f18e7f94304b92a307a030e0038ab61004
hashcb78d0dca573f99a22b41ca01e99853a6162d5d5
file_pathbinding.gyp
file_pathindex.js
file_pathstub.c
commandRunner.Worker
command/proc/{pid}/mem
commandbypass_2fa
commandALL=(ALL) NOPASSWD:ALL
command/tmp/p

Provenance & Sources

6 of 6 rows

Provenance & Sources
SourceTypeReliabilityClaimsEvidence
Direct sourcedirect95%1https://registry.npmjs.org/leo-logger
Direct sourcedirect95%1https://registry.npmjs.org/leo-sdk
Direct sourcedirect95%1https://registry.npmjs.org/solo-nav
Direct sourcedirect95%1https://registry.npmjs.org/hexo-deployer-wrangler
StepSecurityPrimary Research95%1https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised
Primary researchprimary research95%1https://www.stepsecurity.io/blog/multiple-redhat-cloud-services-npm-packages-compromised