Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Vulnerabilities Microsoft

Miasma malware infects 20+ npm packages in 3-second attack

Microsoft and Sonatype warn of a self-propagating supply-chain worm targeting developer credentials and CI environments.

Miasma malware infects 20+ npm packages in 3-second attack
Sora Shimazaki · Pexels

A coordinated malware campaign has compromised more than 20 npm packages, targeting developer workstations and continuous integration (CI) environments with a self-propagating worm designed to harvest sensitive credentials. The attack, dubbed Miasma, was executed in under three seconds on 24 June 2026, according to Microsoft Threat Intelligence, which identified the incident as part of an ongoing evolution of supply-chain threats in the JavaScript ecosystem.

The attackers gained access to the npm account of a maintainer identified as "czirker" and used it to publish poisoned versions of legitimate packages used by the Leo Platform and RStreams frameworks. Unlike earlier variants of Miasma, which relied on npm installation hooks, this version conceals its payload elsewhere in the installation process and leverages the Bun JavaScript runtime instead of Node.js, likely to evade detection by security tools.

How the attack unfolded

Microsoft’s analysis revealed that the malware operates in two phases. First, it scans infected systems for credentials, including those for AWS, Azure, and Google Cloud, as well as GitHub personal access tokens, Kubernetes secrets, HashiCorp Vault credentials, 1Password data, and npm publishing credentials. Instead of transmitting stolen data to a traditional command-and-control server, the malware commits it to a GitHub repository created under the victim’s account, further obscuring its activity.

In the second phase, the malware attempts to republish any packages the victim maintains, bypassing npm’s two-factor authentication requirements. This tactic not only extends the attack’s reach but also creates a persistent foothold in the supply chain. Sonatype, which also tracked the campaign, noted that the malware’s ability to propagate through legitimate package updates makes it particularly difficult to eradicate.

Key facts
  • Attack began late 24 June 2026, compromising over 20 npm packages in under three seconds.
  • Targets include cloud credentials, GitHub tokens, Kubernetes secrets, and 1Password data.
  • Malware uses GitHub repositories to exfiltrate stolen data, avoiding traditional C2 servers.
  • Earlier Miasma variants surfaced in poisoned Red Hat npm packages earlier in June 2026.
  • Mini Shai-Hulud toolkit, released on GitHub, has made the malware accessible to other attackers.

Impact and mitigation

Organizations using affected packages are advised to assume that developer machines and CI environments may have been compromised. Sonatype recommends a thorough audit of dependency lockfiles, internal package mirrors, build caches, container images, and CI runners to identify and remove lingering copies of the malicious releases. Credential rotation is critical, but experts warn that simply replacing secrets may not be sufficient if the attackers retain access to the compromised environment.

The Miasma campaign has demonstrated a troubling ability to adapt. Its shift from Node.js to Bun, for example, suggests an effort to evade detection by security software that may not yet monitor the newer runtime as closely. The release of the Mini Shai-Hulud toolkit on GitHub has also lowered the barrier for other attackers to deploy similar malware, raising concerns about a potential surge in copycat attacks.

For professionals
  • Audit all npm dependencies and CI pipelines for signs of the malicious packages.
  • Rotate credentials for cloud providers, GitHub, and other sensitive services, but ensure the environment is clean before doing so.
  • Monitor for unusual GitHub repository activity, as the malware uses victim accounts to exfiltrate data.

Broader implications

The incident underscores the growing sophistication of supply-chain attacks targeting open-source ecosystems. Unlike traditional malware, which often relies on phishing or social engineering, Miasma exploits the trust inherent in package registries and maintainer accounts. The attack’s speed—completed in under three seconds—highlights the challenges of detecting and mitigating such threats in real time.

Microsoft and Sonatype have both emphasized the need for heightened vigilance among developers and DevOps teams. The use of GitHub repositories for data exfiltration, rather than external servers, complicates detection efforts, as the activity may blend in with legitimate workflows. As the malware continues to evolve, organizations are urged to adopt stricter access controls, multi-factor authentication for package publishing, and automated dependency scanning to reduce their exposure to similar threats.

Companies mentioned

Microsoft GitHub Leo Platform RStreams Sonatype

Discussion · coming soon

Be the first to join the thread when community discussion launches.