Published June 3, 2026 ยท Added June 6, 2026

Trojanized ai-sdk-ollama Delivers Miasma, a Self-Replicating npm Worm via binding.gyp

Endor Labs reports that trojanized ai-sdk-ollama releases were part of the Miasma npm worm campaign, using binding.gyp install hooks to execute malware, steal cloud credentials, and spread through maintainer accounts across developer machines, CI systems, and AI coding agent environments.

Endor Labs reports that trojanized ai-sdk-ollama releases were part of the Miasma npm worm campaign, using binding.gyp install hooks to execute malware, steal cloud credentials, and spread through maintainer accounts across developer machines, CI systems, and AI coding agent environments.

Read the original story.

Source: Endorlabs