<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Supply Chain Attack Hits 32 Red Hat NPM Packages

Hackers hit Red Hat's NPM, injecting malware in 32 packages. Users must update and secure credentials as 10M downloads are compromised.
Content Team

Hackers targeted Red Hat's NPM repository Monday, publishing malicious versions of 32 packages in just 72 seconds — almost certainly automated. The poisoned packages span Red Hat's entire Hybrid Cloud Console JavaScript ecosystem, with nearly 10 million collective downloads combined.

The malware, linked to a worm called "Mini Shai-Hulud" from hacking group TeamPCP, harvests GitHub secrets, cloud credentials, SSH keys, Kubernetes material, and more — then exfiltrates everything to attacker-controlled servers. At least 210 repositories containing stolen credentials have already been identified.

Red Hat has published clean versions of all 32 packages. Anyone who installed a compromised version should treat their environment as breached and rotate all credentials immediately.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo