Supply Chain Attack on Red Hat Cloud Services: Miasma Malware Distributes Malicious npm Packages (heise.de)
0xBASE INTEL BRIEF
- 96 malicious npm package versions in @redhat-cloud-services namespace
- Over 100,000 weekly downloads of affected packages
- Malware steals AWS credentials, SSH keys, crypto wallets, and tokens
"In mid-May, cybercriminals used a clone of the Mini Shai-Hulud worm called Miasma in a supply chain attack, distributing 96 malicious versions of 32 npm packages in the @redhat-cloud-services namespace. The packages were downloaded over 100,000 times weekly. Red Hat has stopped the attack waves and states customer environments are unaffected. The malware steals AWS credentials, SSH keys, crypto wallets, and tokens. Security experts recommend rotating credentials."
#npm supply-chain attack
#Red Hat cloud compromise
#Miasma infostealer
no comments yet.