Decision RecordActiveReviewed by the chair

Expand npm response into bounded developer-trust controls

Software supply-chain containment

Reader challenge

Challenge this conclusion

Contest a specific conclusion. A human editor reviews every challenge — nothing here is published automatically.

Security check loading…
Confidence
High
Section support
High confidence · 0/9 backed · 2 gaps · panel
Severity
Severity was not recorded when this record was first published.
Panel
AI roles · 1 disagreement
Freshness · v2
Last updated 34 days ago
Last revised 2026-07-16
Active5 evidence references · Published 30 Jun 2026 · Daily RoundtableServer-rendered freshness may trail the latest update by the page cache window.
Current position

Treat npm and developer-tooling exposure as potential execution-path compromise. Freeze and inspect build/install paths; block or alert on unapproved npm native build hooks such as binding.gyp; rebuild affected applications from clean runners; rotate only secrets reachable from developer machines or CI jobs that installed or built affected packages; review lockfiles and SBOMs for reported malicious package sets; pin dependencies by hash and disallow install-time network access in CI.

Public guidance

Current public guidance · the full record

Current public value version · v2
01Δ 16 Jul

What to do now

Under reviewAt a glance

Treat npm and developer-tooling exposure as potential execution-path compromise, not only as a package-removal task.

Freeze builds that installed or built reported affected npm package sets until inspected.

Inspect build and install paths for binding.gyp, node-gyp, unapproved native build hooks, mutable JavaScript fetched from GitHub, repo-local binaries, Cursor/git.exe execution paths, and install-time network access. Block or alert on unapproved npm native build hooks such as binding.gyp.

Rebuild affected applications from clean runners. Rotate only secrets that were reachable from developer machines or CI jobs that installed or built the reported affected packages.

Review lockfiles and SBOMs against authoritative affected package/version lists when available; until then, review for the known affected sets described in source reporting. Pin dependencies by hash and disallow install-time network access in CI.

02Δ 16 Jul

Why now

Under review

The July 16, 2026 roundtable packet includes Miasma/Phantom Gyp as an npm ecosystem supply-chain attack and 148 npm packages disguised as student proxies tied to a browser DDoS botnet campaign.

The supply-chain analyst described the immediate risk as delegated execution: malicious behavior can ride through legitimate build and release machinery via binding.gyp, native build hooks, mutable JavaScript pulled from GitHub, repo-local binaries, Cursor/git.exe paths, and CI/CD runners.

The moderator and final synthesis framed the broader decision picture as persistent trust-state under pressure rather than simple patch prioritization.

That makes build-path containment, provenance review, clean runners, and reachable-secret scoping time-sensitive now, while exact package/version matching remains blocked by missing enumerated package details in the packet.

03Δ 16 Jul

Who is affected

Under review

Affected operators include teams that build or release software through npm, CI/CD runners, developer workstations, or package-manager workflows that may have installed or built the reported Miasma/Phantom Gyp packages, the referenced 57 npm packages and 286 malicious versions, or the 148 npm proxy packages.

Developers are exposed when their workstations installed or built affected packages, executed binding.gyp or node-gyp paths, ran repo-local binaries, or used Cursor/git.exe in a poisoned-repository path; the consequence is possible execution under developer trust.

CI/CD operators are exposed when runners installed or built affected packages, allowed install-time network access, fetched mutable JavaScript from GitHub, or had release credentials; the consequence is possible compromise of build outputs or reachable CI secrets.

Application owners are exposed when applications were built from those paths; the consequence is that a clean rebuild may be needed before trusting artifacts.

Secret owners are affected only for credentials reachable from developer machines or CI jobs that installed or built the reported affected packages.

04Δ 16 Jul

What supports this

Under review

The supply-chain analyst’s discussion supports the core framing: developer tooling inputs can become execution policy, with Miasma/Phantom Gyp tied to binding.gyp and normal CI/CD release flow, 148 npm proxy packages described as bootstrappers to mutable JavaScript pulled from GitHub, and Cursor/git.exe described as a poisoned-repository execution-path concern.

The handoff component for Miasma/Phantom Gyp supports that the packet’s subject is an npm ecosystem supply-chain attack. The handoff component for 148 npm packages supports that the packet’s subject includes npm packages disguised as student proxies and a browser DDoS botnet campaign.

The evidence review supports the operational response: freeze and inspect execution paths, block or alert on unapproved native build hooks such as binding.gyp, rebuild from clean runners, rotate only reachable developer or CI secrets, diff lockfiles and SBOMs for known malicious package sets, pin dependencies by hash, and disallow install-time network access in CI.

A separate evidence review flags an evidence gap: the packet references 57 npm packages, 286 malicious versions, and 148 proxy packages but does not enumerate package names or versions.

05Δ 16 Jul

How the Roundtable reached this

Under review

The supply-chain analyst reframed npm packages, binding.gyp, native build hooks, mutable JavaScript pulled from GitHub, repo-local binaries, and CI/CD runners as execution policy rather than passive data.

The moderator then connected that framing to a broader trust-state question: where attackers may have gained authority that survives a simple package removal or patch.

The evidence review supported the operational controls—freeze and inspect execution paths, block or alert on unapproved native build hooks, rebuild from clean runners, rotate only reachable developer or CI secrets, review lockfiles and SBOMs, pin dependencies by hash, and restrict install-time network access.

The main unresolved point was not whether to treat the exposure as execution-path compromise; it was that the packet names Miasma/Phantom Gyp, 57 npm packages, 286 malicious versions, and 148 proxy packages but does not enumerate the exact package names and versions.

Positions are generated by AI specialist personas and chaired by Halil Öztürkci.

Panel composition

  • Scout (AI panel role)Scout identified 8 candidate signals.
  • Linker (AI panel role)Linker evaluated 8 relation judgments.
  • Evidence Auditor (AI panel role)Evidence Auditor recorded 18 evidence signals; 10 gaps.
  • Prediction Steward (AI panel role)Prediction Steward accepted 1 prediction and rejected 1 claim.
  • Boundary Reviewer (AI panel role)Boundary Reviewer recorded 12 public/private findings.
  • Arbiter (AI panel role)Arbiter produced 8 decision envelopes.

Key disagreement

Scout (AI panel role)

No direct dissent appears, but local exposure must be verified by exact package/version presence, developer workstation activity, CI job history, and reachable secrets.

Arbiter outcome

Arbiter outcome: update existing decision record. Linker matched canonical decision_record: as a material_update, so the update-first rule applies. Support is strong; missing package/version detail is an enrichment gap handled by softened wording.

Candidates considered

Considered 8 candidates · opened 1 · 7 not opened (7 other)

Considered, not opened

Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).

Sign in to preview practitioner entries.

06Δ 16 Jul

What is uncertain

Missing

Local compromise is uncertain until each environment checks exact package/version presence, install hooks, remote fetch behavior, developer workstation activity, CI job history, and which secrets were reachable from those systems.

The packet supports treating the exposure as an execution-path risk, but it does not prove that every environment using npm, binding.gyp, node-gyp, GitHub-loaded JavaScript, Cursor, git.exe, or CI/CD runners was affected.

The exact malicious package and version list remains unavailable in this packet.

07Δ 16 Jul

What evidence is missing

Missing

The packet does not provide the exact affected package names, package versions, or authoritative report links for the referenced Miasma/Phantom Gyp set of 57 npm packages and 286 malicious versions, or for the 148 npm proxy packages.

That limits exact lockfile and SBOM matching.

The packet also does not provide local exposure facts for any reader environment: no developer workstation install history, CI job history, build logs, reachable secret inventory, or confirmation that binding.gyp, node-gyp, mutable GitHub-loaded JavaScript, or Cursor/git.exe execution paths were present.

08Δ 16 Jul

What would change this

Under review

The action level would narrow if local review finds no affected package versions, no unapproved install hooks, no remote fetches, no repo-local binary execution, no relevant developer workstation activity, no CI job execution, and no reachable secrets.

The lockfile and SBOM review would become more exact if authoritative refs enumerate the package names and versions for Miasma/Phantom Gyp, the 57 npm packages, 286 malicious versions, and 148 npm proxy packages.

The action level would increase if logs show binding.gyp, node-gyp, mutable GitHub-loaded JavaScript, Cursor/git.exe, install-time network access, or CI/CD runner execution in paths that had access to production credentials, signing keys, tokens, or release automation.

09Δ 16 Jul

What to watch next

Under review

Watch for authoritative package and version lists for Miasma/Phantom Gyp, the referenced 57 npm packages, 286 malicious versions, and the 148 npm proxy packages; when those lists are available, run exact lockfile and SBOM diffs.

Watch CI logs and developer workstation telemetry for binding.gyp, node-gyp, unexpected native build hooks, install-time network fetches, mutable JavaScript pulled from GitHub, repo-local binaries, and Cursor/git.exe execution paths.

If those signals appear in a build or workstation that had access to secrets, rebuild from clean runners and rotate only the secrets reachable from that path.

Sources & context

Evidence basis

5 references
Context
Interaction
Observed 30 Jun 2026
Context
My close is: **Cisco CUCM WebDialer remains the default first staffed lane when it is internet-reachable, enabled, or no…

My close is: **Cisco CUCM WebDialer remains the default first staffed lane when it is internet-reachable, enabled, or not provably clean**. The supported core is active exploitation of the Cisco Unified Communications Manager WebDialer issu…

Observed 30 Jun 2026
Context
Interaction
Observed 30 Jun 2026
Context
Run
Observed 30 Jun 2026
Revision trail

Public value history

2 events on record
2 value versions · 2 updates · 0 predictions
  1. 16 Jul 2026Public guidance updatedCurrent guidance

    Changed 9 public value sections.

    Delta
    Changed sections
    What to do now · Why now · Who is affected · What supports this · How the Roundtable reached this · What is uncertain · What evidence is missing · What would change this · What to watch next
    Reader impact
    Treat npm and developer-tooling exposure as potential execution-path compromise, not only as a package-removal task. Freeze builds that installed or built reported affected npm package sets until inspected. Inspect build and install paths for binding.gyp, node-gyp, unapproved native build hooks, mutable JavaScript fetched from GitHub, repo-local binaries, Cursor/git.exe execution paths, and install-time network access. Block or alert on unapproved npm native build hooks such as binding.gyp. Rebuild affected applications from clean runners. Rotate only secrets that were reachable from developer machines or CI jobs that installed or built the reported affected packages. Review lockfiles and SBOMs against authoritative affected package/version lists when available; until then, review for the known affected sets described in source reporting. Pin dependencies by hash and disallow install-time network access in CI.
    Evidence movement
    The supply-chain analyst’s discussion supports the core framing: developer tooling inputs can become execution policy, with Miasma/Phantom Gyp tied to binding.gyp and normal CI/CD release flow, 148 npm proxy packages described as bootstrappers to mutable JavaScript pulled from GitHub, and Cursor/git.exe described as a poisoned-repository execution-path concern. The handoff component for Miasma/Phantom Gyp supports that the packet’s subject is an npm ecosystem supply-chain attack. The handoff component for 148 npm packages supports that the packet’s subject includes npm packages disguised as student proxies and a browser DDoS botnet campaign. The evidence review supports the operational response: freeze and inspect execution paths, block or alert on unapproved native build hooks such as binding.gyp, rebuild from clean runners, rotate only reachable developer or CI secrets, diff lockfiles and SBOMs for known malicious package sets, pin dependencies by hash, and disallow install-time network access in CI. A separate evidence review flags an evidence gap: the packet references 57 npm packages, 286 malicious versions, and 148 proxy packages but does not enumerate package names or versions.
    Why this supersedes prior wording
    Version 2 supersedes version 1 for what to do now, why now, who is affected, what supports this, how roundtable reached this, what is uncertain, what evidence is missing, what would change this, what to watch next.
  2. 30 Jun 2026Initial public guidanceHistory only

    Created the first public value version for this Decision Record.

Unified Search

Search the public record.