Miasma Worm Forges SLSA Provenance and Hides in binding.gyp as It Hits Red Hat, Vapi, and Leo Platform npm Packages
A self-spreading npm worm called Miasma published Trojanized packages carrying valid-looking SLSA provenance, beginning with 32 @redhat-cloud-services releases on June 1.