Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The Magnetophon and the Birth of the Laugh Track

    August 2, 2026

    Page Not Found | WIRED

    August 2, 2026

    This Week’s Awesome Tech Stories From Around the Web (Through August 1)

    August 1, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Magnetophon and the Birth of the Laugh Track
    • Page Not Found | WIRED
    • This Week’s Awesome Tech Stories From Around the Web (Through August 1)
    • Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal
    • The Man Who Understood Risk: Robert N. Charette retires.
    • 7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
    • Gemini Robotics 2 Brings Google’s AI Into the Physical World
    • This AI Assistant Wants to Make Up for Your Boyfriend’s Incompetence
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Red Hat npm packages compromised in new Mini Shai-Hulud malware wave
    Cybersecurity

    Red Hat npm packages compromised in new Mini Shai-Hulud malware wave

    kirklandc008@gmail.comBy kirklandc008@gmail.comJune 2, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    IBM and Red Hat are betting $5 billion that open source needs a security guard
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Unknown attackers have compromised 30+ Red Hat Cloud Services npm packages with malware that goes after credentials stored in developers’ build environment.

    What the malware stole and how it can spread further

    The compromised packages were published in two different GitHub source repositories on June 1, 2026, between 10:53 and 10:53:33 UTC and 13:44 and 13:46:47 UTC.

    According to Wiz Security, a specific Red Hat employee GitHub account was compromised and “pushed malicious orphan commits to two RedHatInsights repositories, bypassing code review.”

    It’s currently unknown how the employee’s GitHub account was compromised.

    “The malware operates via a preinstall lifecycle hook that executes a 4.2 MB obfuscated JavaScript payload during npm install, before any application code runs,” Orca researchers explained.

    It searchers for and exfiltrates AWS, GCP and Azure keys, tokesn and credentials, GitHub Actions tokens, HashiCorp Vault tokens, Kubernetes credentials and configuration files, SSH private keys, npm and PyPI publish tokens, and more.

    The malicious payload seems to be a new version of TeamPCP’s Mini Shai-Hulud malware, which was used by the threat actors in previous supply chain attacks and open-sourced by them in May 2026.

    “Using harvested npm authentication tokens, the payload attempts to publish new backdoored versions of packages the victim account has access to. Critically, it uses npm’s bypass_2fa publish parameter to override two-factor authentication requirements,” StepSecurity researchers noted.

    “This capability is available to automation tokens and is used here to make the worm self-propagating even against accounts with 2FA enabled. Each successfully infected machine can autonomously seed the next wave of compromised packages without any further attacker involvement.”

    According to Wiz researchers, this new variant has been equipped with new data collectors for cloud identities, and generates a uniquely encrypted payload for each infection.

    “This variant creates repositories containing the description Miasma: The Spreading Blight,” they added.

    Whether this attack was the work of TeamPCP or copycat attackers is also currently unknown.

    Red Hat’s response and recommended actions

    Red Hat removed most of the infected packages from the npm registry within two hours of publication, and said that “the packages are strictly limited to internal development, and the malicious code was never published for customer consumption via the console.redhat.com system.”

    There’s currently no evidence of the attack having had an impact on customer or partner environments or Red Hat production systems, they added.

    But developers and organizations that have installed one or more of the compromised package versions must do damage control.

    Wiz researchers advise:

    • Investigating developer workstations, CI/CD environments, and repositories for signs of compromise
    • Auditing systems for the affected packages, GitHub Actions, and VSCode extensions
    • Reviewing GitHub activity for unauthorized repositories, newly created access tokens, or suspicious workflow executions
    • Rotating all keys, credentials and tokens that may have been accessed and harvested

    “Finally, organizations should strengthen software supply chain defenses by implementing dependency allowlisting, SBOM generation, package verification, and improved monitoring of developer and build environments,” they added.

    Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

    compromised HAT malware Mini npm packages Red ShaiHulud wave
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • The Magnetophon and the Birth of the Laugh Track
    • Page Not Found | WIRED
    • This Week’s Awesome Tech Stories From Around the Web (Through August 1)
    • Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal
    • The Man Who Understood Risk: Robert N. Charette retires.

    The Magnetophon and the Birth of the Laugh Track

    August 2, 2026

    Page Not Found | WIRED

    August 2, 2026

    This Week’s Awesome Tech Stories From Around the Web (Through August 1)

    August 1, 2026

    Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal

    August 1, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.