<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Supply Chain Attack Hits 32 Red Hat NPM Packages

Hackers hit Red Hat's NPM, injecting malware in 32 packages. Users must update and secure credentials as 10M downloads are compromised.
Content Team

Attackers published malicious versions of 32 packages in Red Hat's @redhat-cloud-services npm scope on Monday, June 1 — all within 72 seconds, pointing to automation. Researchers traced the entry point to a compromised Red Hat employee GitHub account, with GitHub Actions OIDC credentials used to publish. The affected packages have drawn nearly 10 million downloads over their lifetime.

The malware is a variant of the "Mini Shai-Hulud" worm, carrying the internal name "Miasma: The Spreading Blight." It harvests GitHub secrets, npm tokens, cloud credentials, SSH keys, Kubernetes and Vault material and more, then exfiltrates to attacker-controlled servers. At least 210 repositories containing stolen credentials have been identified.

Attribution is open. TeamPCP released this worm's source code publicly the previous month, so researchers say it could be TeamPCP or a copycat.

Critically, the payload ran from a preinstall hook — it executed during npm install, before the package was ever imported. Whether your code called the library is irrelevant.

Red Hat has published clean versions of all 32 packages and removed the malicious ones. It says the packages were limited to internal development, never published for customer consumption, and that it found no impact to customer or partner environments.

If you installed a compromised version, treat the environment as breached. Rotate every reachable credential, check lockfiles and CI logs for the affected versions, and rebuild from clean environments rather than reusing runners, workspaces or cached node_modules.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo