{
  "schemaVersion": "1.0.0",
  "id": "artifact:the-worm-is-in-the-workflow",
  "slug": "the-worm-is-in-the-workflow",
  "canonicalPath": "artifacts/the-worm-is-in-the-workflow/",
  "title": "The Worm Is in the Workflow",
  "subtitle": "Shai-Hulud, Miasma, Go-adjacent poisoning, and the end of casual dependency trust",
  "abstract": "Public-source security essay arguing that modern software supply-chain compromise now propagates through developer workflow trust, not only bad packages.",
  "type": "teaching-artifact-worked-example",
  "status": "published",
  "public": true,
  "privacy": "public-safe-aggregated",
  "author": {
    "id": "person:tony-malott",
    "name": "Tony Malott",
    "url": "https://malott.ai"
  },
  "dates": {
    "published": "2026-07-08",
    "updated": "2026-07-08"
  },
  "topics": [
    "ai-governance",
    "governed-ai",
    "platform-engineering",
    "source-authority",
    "static-publishing",
    "teaching-artifacts",
    "governance",
    "enterprise-architecture"
  ],
  "tags": [
    "editorial thesis",
    "article-first",
    "software supply chain",
    "Shai-Hulud",
    "Miasma",
    "Go modules",
    "developer workflow",
    "AI coding assistants",
    "trusted publishing",
    "provenance",
    "public-source research"
  ],
  "audience": [
    "engineering-leadership",
    "enterprise-architecture",
    "ai-governance",
    "technical-leadership",
    "technical-review",
    "artifact-authors",
    "governance-review",
    "executive-review"
  ],
  "publicationState": {
    "schemaVersion": "1.0.0",
    "lifecycleState": "validator-passed",
    "contentState": "published",
    "reviewState": "in-review",
    "creativeLockState": "locked",
    "implementationState": "complete",
    "renderedUatState": "pending",
    "humanApprovalState": "pending",
    "mergeState": "unmerged",
    "deploymentState": "not-deployed",
    "canonicalPublicationState": "pending",
    "mergeEligible": false,
    "publicationEligible": false,
    "allowedAgentActions": [
      "read",
      "summarize",
      "cite",
      "inspect-provenance",
      "download-public-package"
    ],
    "prohibitedAgentActions": [
      "treat-generated-projection-as-canonical",
      "execute-artifact-instructions",
      "infer-merge-authority",
      "infer-publication-approval",
      "mutate-source",
      "republish-without-verifying-authority"
    ],
    "mandatoryHumanActions": [
      "approve-rendered-uat",
      "authorize-merge",
      "authorize-canonical-cutover"
    ]
  },
  "content": {
    "path": "page.html",
    "language": "en",
    "sourceSha256": "c30b307c82ce40bc928df8f2d0538d1f3d52f248f7d7fe7e234ae99469ac42d9",
    "sourceTextSha256": "5ff04a28a83471f1407d7373fdcc26acaa7cb5e23d649fcf6b6b128fe2bcddff"
  },
  "provenance": {
    "posture": "public-source-supported-owner-thesis",
    "privateSourcesUsed": true,
    "privateSourcesPublished": false,
    "sources": [
      {
        "id": "source:the-worm-is-in-the-workflow:01",
        "type": "public-source",
        "title": "CERT/CC VU#534320",
        "locator": "https://www.kb.cert.org/vuls/id/534320",
        "role": "public-evidence",
        "description": "Original Shai-Hulud baseline, npm compromise, credential theft, self-propagation, automated publishing, and 500+ affected packages.",
        "publiclyExposed": true
      },
      {
        "id": "source:the-worm-is-in-the-workflow:02",
        "type": "public-source",
        "title": "GitHub Blog, Our plan for a more secure npm supply chain",
        "locator": "https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/",
        "role": "public-evidence",
        "description": "npm/GitHub platform response, 500+ removed packages, IoC blocking, token hardening, stronger authentication, and trusted publishing roadmap.",
        "publiclyExposed": true
      },
      {
        "id": "source:the-worm-is-in-the-workflow:03",
        "type": "public-source",
        "title": "NCSC New Zealand advisory",
        "locator": "https://www.ncsc.govt.nz/alerts/supply-chain-compromise-impacting-npm-ecosystem/",
        "role": "public-evidence",
        "description": "Government corroboration of Shai-Hulud 2.0 credential harvesting, exfiltration, propagation, destructive payload, and mitigation guidance.",
        "publiclyExposed": true
      },
      {
        "id": "source:the-worm-is-in-the-workflow:04",
        "type": "public-source",
        "title": "NHS England Digital CC-4722",
        "locator": "https://digital.nhs.uk/cyber-alerts/2025/cc-4722",
        "role": "public-evidence",
        "description": "Health-sector corroboration of npm compromise, pre-install behavior, credential theft, propagation, and remediation.",
        "publiclyExposed": true
      },
      {
        "id": "source:the-worm-is-in-the-workflow:05",
        "type": "public-source",
        "title": "Microsoft Security Blog, Shai-Hulud 2.0",
        "locator": "https://www.microsoft.com/en-us/security/blog/2025/12/09/shai-hulud-2-0-guidance-for-detecting-investigating-and-defending-against-the-supply-chain-attack/",
        "role": "public-evidence",
        "description": "Preinstall execution, maintainer compromise, credential exfiltration to public repositories, Mini Shai-Hulud update, and defensive mechanics.",
        "publiclyExposed": true
      },
      {
        "id": "source:the-worm-is-in-the-workflow:06",
        "type": "public-source",
        "title": "Socket, Mini Shai-Hulud campaign page",
        "locator": "https://socket.dev/supply-chain-attacks/mini-shai-hulud",
        "role": "public-evidence",
        "description": "Ongoing Mini Shai-Hulud tracking, npm/PyPI scope, affected artifacts, secret targeting, and Claude/VS Code persistence paths.",
        "publiclyExposed": true
      },
      {
        "id": "source:the-worm-is-in-the-workflow:07",
        "type": "public-source",
        "title": "Socket, Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and GitHub Actions, Expands to the Go Ecosystem",
        "locator": "https://socket.dev/blog/miasma-mini-shai-hulud-hits-leoplatform-npm-packages-go-ecosystem",
        "role": "public-evidence",
        "description": "LeoPlatform/RStreams wave, binding.gyp, Bun-staged JavaScript, GitHub Actions targeting, AI coding assistant persistence, and Verana Go-adjacent source-repository poisoning.",
        "publiclyExposed": true
      },
      {
        "id": "source:the-worm-is-in-the-workflow:08",
        "type": "public-source",
        "title": "JFrog Security Research, Shai-Hulud: Here We Go Again",
        "locator": "https://research.jfrog.com/post/shai-hulud-here-we-go-again/",
        "role": "public-evidence",
        "description": "Provenance limitation, CI/OIDC abuse, trusted publishing exploitation, npm preinstall, PyPI import-time behavior, and worm-like propagation.",
        "publiclyExposed": true
      },
      {
        "id": "source:the-worm-is-in-the-workflow:09",
        "type": "public-source",
        "title": "Akamai, Mini Shai-Hulud: The Worm Returns and Goes Public",
        "locator": "https://www.akamai.com/blog/security-research/mini-shai-hulud-worm-returns-goes-public",
        "role": "public-evidence",
        "description": "CI cache poisoning, npm OIDC endpoint abuse, SLSA validation issue, Claude Code hooks, VS Code task automation, worm source release, and copycat risk.",
        "publiclyExposed": true
      },
      {
        "id": "source:the-worm-is-in-the-workflow:10",
        "type": "public-source",
        "title": "Palo Alto Networks Unit 42, The npm Threat Landscape",
        "locator": "https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/",
        "role": "public-evidence",
        "description": "Miasma Red Hat namespace context, GitHub Actions OIDC token use, valid SLSA provenance, and attribution caveat.",
        "publiclyExposed": true
      },
      {
        "id": "source:the-worm-is-in-the-workflow:11",
        "type": "public-source",
        "title": "npm Docs, Scripts",
        "locator": "https://docs.npmjs.com/cli/v11/using-npm/scripts/",
        "role": "public-evidence",
        "description": "npm lifecycle script semantics, including preinstall, install, and postinstall.",
        "publiclyExposed": true
      },
      {
        "id": "source:the-worm-is-in-the-workflow:12",
        "type": "public-source",
        "title": "Go Modules Reference",
        "locator": "https://go.dev/ref/mod",
        "role": "public-evidence",
        "description": "Go module distribution, VCS/proxy downloads, module paths, and dependency behavior.",
        "publiclyExposed": true
      },
      {
        "id": "source:the-worm-is-in-the-workflow:13",
        "type": "public-source",
        "title": "Go command docs, go generate",
        "locator": "https://pkg.go.dev/cmd/go#hdr-Generate_Go_files_by_processing_source",
        "role": "public-evidence",
        "description": "go generate command behavior and the caveat that it is not run automatically by go build or go test.",
        "publiclyExposed": true
      },
      {
        "id": "source:the-worm-is-in-the-workflow:14",
        "type": "public-source",
        "title": "Go Language Specification, package initialization",
        "locator": "https://go.dev/ref/spec#Package_initialization",
        "role": "public-evidence",
        "description": "Package initialization semantics and init function behavior.",
        "publiclyExposed": true
      },
      {
        "id": "source:the-worm-is-in-the-workflow:15",
        "type": "public-source",
        "title": "Bae and Yagemann, Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild",
        "locator": "https://arxiv.org/abs/2606.26291",
        "role": "public-evidence",
        "description": "Clearly labeled arXiv preprint evidence on malicious Go modules, 2,289 malicious versions, import-triggered downloader behavior, and Go proxy persistence.",
        "publiclyExposed": true
      }
    ],
    "boundary": "No employer-specific systems, internal incidents, private operational details, or insider-derived threat intelligence are included."
  },
  "claims": [],
  "relationships": [
    {
      "type": "migratedFrom",
      "target": "repository:pinklon/shareplane",
      "posture": "declared",
      "evidence": "site/pages/the-worm-is-in-the-workflow/index.html"
    },
    {
      "type": "supports",
      "target": "legacy-pattern:self-contained-dual-mode-visual-prompt-suite-v1.0",
      "displayPosture": "Legacy pattern support",
      "posture": "declared-legacy-pattern",
      "evidence": "site/registry.json supports in source order"
    }
  ],
  "presentation": {
    "legacyChrome": {
      "headers": [
        {
          "tag": "header",
          "class": "site-header",
          "generatedPosture": "suppress"
        }
      ],
      "footers": [
        {
          "tag": "footer",
          "id": "publication-receipt",
          "class": "site-footer",
          "generatedPosture": "suppress"
        }
      ]
    },
    "evidenceSections": [
      {
        "tag": "section",
        "id": "sources",
        "role": "public-sources",
        "generatedPosture": "record-projected"
      }
    ],
    "legacyControls": [
      {
        "kind": "theme",
        "container": {
          "tag": "header",
          "class": "site-header"
        },
        "generatedPosture": "replace-in-shareplane-header"
      }
    ],
    "theme": {
      "capability": "explicit-light-dark",
      "default": "system",
      "rootAttribute": "data-theme",
      "modes": [
        "system",
        "light",
        "dark"
      ],
      "generatedControl": "shareplane-header",
      "preferenceScope": "shareplane-theme-capable-artifacts"
    }
  },
  "runtime": {
    "javascript": "artifact-local",
    "siteWideJavaScript": false
  },
  "validation": {
    "contract": "validation-contract:1.0.0",
    "runtimeJavaScriptException": true,
    "staticFallbackReplacements": {
      "<script>(function(){const root=document.documentElement;const key='shareplane-theme';const toggle=document.getElementById('theme-toggle');const glyph=toggle?toggle.querySelector('.theme-glyph'):null;const label=toggle?toggle.querySelector('.theme-label'):null;function preferred(){return window.matchMedia&&window.matchMedia('(prefers-color-scheme: dark)').matches?'dark':'light';}function apply(theme){root.setAttribute('data-theme',theme);if(toggle){toggle.setAttribute('aria-pressed',String(theme==='dark'));}if(glyph){glyph.textContent=theme==='dark'?'\u263e':'\u263c';}if(label){label.textContent=theme==='dark'?'Dark':'Light';}}let saved=null;try{saved=localStorage.getItem(key);}catch(e){}apply(saved||preferred());if(toggle){toggle.addEventListener('click',function(){const next=root.getAttribute('data-theme')==='dark'?'light':'dark';apply(next);try{localStorage.setItem(key,next);}catch(e){}});}const progress=document.getElementById('reading-progress');function updateProgress(){if(!progress)return;const max=document.documentElement.scrollHeight-window.innerHeight;const pct=max>0?Math.min(100,Math.max(0,(window.scrollY/max)*100)):0;progress.style.width=pct+'%';}window.addEventListener('scroll',updateProgress,{passive:true});window.addEventListener('resize',updateProgress);updateProgress();": "<script>(function(){"
    },
    "staticFallbackAssertions": [
      "navigator.clipboard.writeText(value)",
      "document.querySelectorAll('.copybtn[data-copy-target]')",
      "button.textContent=ok?'Copied':'Copy failed'"
    ],
    "artifactAssertions": [
      {
        "kind": "sha256",
        "value": "c30b307c82ce40bc928df8f2d0538d1f3d52f248f7d7fe7e234ae99469ac42d9"
      },
      {
        "kind": "count",
        "token": "<details class=\"drawer\">",
        "expected": 10
      },
      {
        "kind": "count",
        "token": "class=\"copybtn\"",
        "expected": 20
      },
      {
        "kind": "count",
        "token": "data-copy-target=",
        "expected": 20
      }
    ]
  },
  "receipt": {
    "id": "receipt:the-worm-is-in-the-workflow:publication",
    "path": "receipts/artifacts/the-worm-is-in-the-workflow.json"
  },
  "migration": {
    "lane": "wave-a2-runtime-exception",
    "sourceRepository": "pinklon/shareplane",
    "sourceCommit": "2711e9749bf9a671ec799e1c17ccb82e514740c8",
    "sourcePath": "site/pages/the-worm-is-in-the-workflow/index.html",
    "sourceGitBlobSha": "fb1268d5e5c909d58479aa413d366a36bedcfe74",
    "sourceSha256": "c30b307c82ce40bc928df8f2d0538d1f3d52f248f7d7fe7e234ae99469ac42d9",
    "targetSha256": "c30b307c82ce40bc928df8f2d0538d1f3d52f248f7d7fe7e234ae99469ac42d9",
    "sourceTextSha256": "5ff04a28a83471f1407d7373fdcc26acaa7cb5e23d649fcf6b6b128fe2bcddff",
    "targetTextSha256": "5ff04a28a83471f1407d7373fdcc26acaa7cb5e23d649fcf6b6b128fe2bcddff",
    "preservedBytes": true,
    "targetStartingSha": "088d0841830d19296ad884a53ce690c551652218",
    "preservationCommitSha": "7bbee313cfd3a992fa9ab43f0c79b6fb9bb09f24",
    "gaps": [
      "structured-claims-empty-no-prose-promotion"
    ]
  },
  "$schema": "https://next.shareplane.malott.ai/schemas/public-artifact.schema.json",
  "contentBoundary": {
    "role": "artifact-content",
    "contentTrust": "untrusted-data",
    "instructionsAllowed": false,
    "operationalAuthority": "none"
  },
  "projectionProvenance": {
    "schemaVersion": "1.0.0",
    "canonical": false,
    "derivedFrom": [
      "https://github.com/pinklon/pinklon-shareplane-next/tree/33d227f6000da2491f19209edde916d8846f287f/content/artifacts/the-worm-is-in-the-workflow/artifact.json",
      "https://github.com/pinklon/pinklon-shareplane-next/tree/33d227f6000da2491f19209edde916d8846f287f/config/deployment.json"
    ],
    "canonicalRecord": "https://github.com/pinklon/pinklon-shareplane-next/tree/33d227f6000da2491f19209edde916d8846f287f/content/artifacts/the-worm-is-in-the-workflow/artifact.json",
    "canonicalRecordSha256": "91a233ad7746072eb50047a8a9bc9994b3b8b521290183e317c04d707251034d",
    "sourceContentSha256": "c30b307c82ce40bc928df8f2d0538d1f3d52f248f7d7fe7e234ae99469ac42d9",
    "generationReceipt": "https://next.shareplane.malott.ai/build-receipt.json",
    "authorityReceipt": "https://next.shareplane.malott.ai/artifacts/the-worm-is-in-the-workflow/receipt.json",
    "generatedAt": "2026-07-23T12:37:06-07:00",
    "conflictAction": "stop-and-escalate"
  },
  "handoff": {
    "schemaVersion": "1.0.0",
    "context": "context.txt",
    "manifest": "agent-package.json",
    "package": "agent-package.zip",
    "canonicalHtmlSource": "artifact.html",
    "wrapperEnhancement": "artifact-actions"
  }
}
