New npm Supply Chain Attack Bypasses Provenance Checks, NCSC Urges Dependency Review
A significant supply chain attack, identified as the 'Miasma' campaign, has successfully compromised 32 npm packages across more than 90 versions, all operating under the trusted @redhat-cloud-services scope. This sophisticated attack, detailed by Microsoft Threat Intelligence on June 2nd, 2026, managed to bypass established checks, including authentic provenance signatures generated through legitimate GitHub Actions OIDC workflows.
The incident underscores a critical vulnerability in the open-source ecosystem, where trust in verified provenance can be exploited. The malicious versions of these packages were able to masquerade as legitimate, highlighting a persistent challenge in securing software supply chains.
In response to this and similar threats, the UK's National Cyber Security Centre (NCSC) has once again urged organizations to meticulously review their open-source dependencies. A blog post published by the NCSC on June 4th, 2026, reiterated long-standing advice on reducing exposure to supply chain attacks. This renewed call to action suggests that many organizations have not adequately implemented previous guidance, despite the growing frequency and sophistication of such attacks.
The NCSC's recommendations include maintaining accurate inventories of dependencies, understanding package origins, monitoring for unexpected changes, and thoroughly assessing the trustworthiness of upstream sources. The Miasma campaign serves as a stark reminder that the threat landscape for software supply chain security continues to evolve, demanding a more proactive and rigorous approach from all organizations.
Read original source