# phantom gyp

Published articles for phantom gyp.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Miasma Phantom Gyp npm attack: 57 packages, 286 malicious versions hijack CI/CD pipelines via binding.gyp

DevFeed: [Miasma Phantom Gyp npm attack: 57 packages, 286 malicious versions hijack CI/CD pipelines via binding.gyp](<https://devfeed.tech/articles/miasma-phantom-gyp-npm-attack-57-packages-286-malicious-versions-hijack-ci-cd-pipelines-via-binding-gyp-12928.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-artifacts-safe-from-miasma-phantom-gyp-npm-attack>)

Published: 2026-06-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Security](<https://devfeed.tech/topics/security.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [npm](<https://devfeed.tech/topics/npm.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-actions](<https://devfeed.tech/tags/chainguard-actions.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [malware](<https://devfeed.tech/tags/malware.md>), [miasma](<https://devfeed.tech/tags/miasma.md>), [npm-security](<https://devfeed.tech/tags/npm-security.md>), [packages](<https://devfeed.tech/tags/packages.md>), [phantom-gyp](<https://devfeed.tech/tags/phantom-gyp.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

This article describes the Miasma Phantom Gyp npm supply-chain attack, in which attackers published 286 malicious versions across 57 packages. The self-replicating worm targeted CI/CD pipelines, harvested credentials, poisoned additional packages, modified workflows, and planted backdoor configurations in AI coding assistant directories. It also explains that Chainguard customers were protected because Chainguard Libraries builds from source and blocked the malicious versions.

### Source excerpt

A new npm supply chain worm compromised 57 packages and 286 versions. Learn how Chainguard blocked the attack and protected customers by design.