0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

Red Hat npm Namespace Compromised in Supply Chain Attack (infosecurity-magazine.com)

· 57d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • 32 packages in @redhat-cloud-services npm scope backdoored
  • Malware steals cloud keys, CI/CD tokens, and npm credentials
  • Exploited GitHub Actions OIDC tokens for pipeline compromise

"On June 1, an attacker published malicious versions of 32 packages in the @redhat-cloud-services npm scope, all within 72 seconds. The packages, part of Red Hat's Hybrid Cloud Console ecosystem, carried obfuscated preinstall scripts that harvested cloud provider keys, CI/CD tokens, and npm credentials. Analysis by ReversingLabs and Aikido Security indicates the malware is a variant of the Mini Shai-Hulud worm, tracked as Miasma. The attacker leveraged GitHub Actions OIDC tokens, indicating a build pipeline compromise. Clean versions have been released and malicious ones removed, but any installation before remediation requires credential rotation."

#npm supply chain #credential-stealing worm #OIDC token abuse

Discussion Matrix

0 segments

no comments yet.