Red Hat npm Namespace Compromised in Supply Chain Attack (infosecurity-magazine.com)
- 32 packages in @redhat-cloud-services npm scope backdoored
- Malware steals cloud keys, CI/CD tokens, and npm credentials
- Exploited GitHub Actions OIDC tokens for pipeline compromise
"On June 1, an attacker published malicious versions of 32 packages in the @redhat-cloud-services npm scope, all within 72 seconds. The packages, part of Red Hat's Hybrid Cloud Console ecosystem, carried obfuscated preinstall scripts that harvested cloud provider keys, CI/CD tokens, and npm credentials. Analysis by ReversingLabs and Aikido Security indicates the malware is a variant of the Mini Shai-Hulud worm, tracked as Miasma. The attacker leveraged GitHub Actions OIDC tokens, indicating a build pipeline compromise. Clean versions have been released and malicious ones removed, but any installation before remediation requires credential rotation."
no comments yet.