
Sources for the above:
SafeDep's full technical teardown of the Miasma toolkit — architecture, C2 mechanics, Sigstore forgery module, LOTP injection, dead-man switch — is the primary technical record: safedep.io/inside-the-mia… (June 9, 2026)
BleepingComputer on the source code leak itself: bleepingcomputer.com/news/security/… (June 10, 2026)
The Register on GitHub's same-day response disabling npm auto-run scripts: theregister.com/devops/2026/06… (June 10, 2026)

English








