# Miasma operator

> As of 2026-06-08, Miasma operator is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning supply chain. ATT&CK coverage spans 34 techniques across 12 tactics in 2 of 2 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1102 (Web Service), T1140 (Deobfuscate/Decode Files or Information).

- **Tracked threats:** 2
- **Categories:** SUPPLY_CHAIN
- **As of:** 2026-06-08

## ATT&CK techniques observed

34 techniques observed across 2 of 2 tracked threats. Tactics: Credential Access (5), Initial Access (5), Stealth (formerly Defense Evasion) (5), Discovery (4), Execution (4), Command and Control (3).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 2 of 2 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1195](https://intel.threadlinqs.com/technique/T1195) Supply Chain Compromise — Initial Access — observed in 2 of 2 tracked threats
- [T1199](https://intel.threadlinqs.com/technique/T1199) Trusted Relationship — Initial Access — observed in 2 of 2 tracked threats
- [T1526](https://intel.threadlinqs.com/technique/T1526) Cloud Service Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1528](https://intel.threadlinqs.com/technique/T1528) Steal Application Access Token — Credential Access — observed in 2 of 2 tracked threats
- [T1546](https://intel.threadlinqs.com/technique/T1546) Event Triggered Execution — Persistence — observed in 2 of 2 tracked threats
- [T1567](https://intel.threadlinqs.com/technique/T1567) Exfiltration Over Web Service — Exfiltration — observed in 2 of 2 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 1 of 2 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 1 of 2 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 1 of 2 tracked threats
- [T1059.004](https://intel.threadlinqs.com/technique/T1059.004) Unix Shell — Execution — observed in 1 of 2 tracked threats
- [T1059.007](https://intel.threadlinqs.com/technique/T1059.007) JavaScript — Execution — observed in 1 of 2 tracked threats

## Tracked threats

- [Miasma Worm Compromises 73 Microsoft GitHub Repositories Across Azure, Azure-Samples, Microsoft & MicrosoftDocs — Self-Replicating Mini Shai-Hulud Variant Weaponizing AI Coding Agents (TeamPCP)](https://intel.threadlinqs.com/threat/TL-2026-0719) — CRITICAL
- [Miasma — @redhat-cloud-services npm Supply Chain Compromise (Mini Shai-Hulud Variant, GitHub Actions OIDC/SLSA Abuse with GCP/Azure Cloud-Identity Theft)](https://intel.threadlinqs.com/threat/TL-2026-0643) — CRITICAL

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Miasma%20operator
