Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    6 Windhawk mods that make Windows 11 behave like it should

    June 15, 2026

    Why I designed Charlotte Tilbury Beauty as a technology company

    June 15, 2026

    Nintendo’s Switch 2 price is increasing to AU$769.95 come Sep 1 — which makes this AU$629 deal for EOFY all the more tempting

    June 15, 2026
    Facebook X (Twitter) Instagram
    Trending
    • 6 Windhawk mods that make Windows 11 behave like it should
    • Why I designed Charlotte Tilbury Beauty as a technology company
    • Nintendo’s Switch 2 price is increasing to AU$769.95 come Sep 1 — which makes this AU$629 deal for EOFY all the more tempting
    • Here's what Jeff Bezos' new startup Prometheus will do
    • Berlin’s Qorelo raises €3 million five months after launch to tackle SAP’s 2027 transformation crunch
    • Chinese Drivers Are Using Tiny Plastic Heads to Fool Tesla’s Autopilot Safeguards
    • 5 new Netflix movies and shows you need to stream this week (June 15-21)
    • Scientists Investigate Strange Rumbling Beneath Utah
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Red Hat npm packages compromised to steal developer credentials
    Cybersecurity

    Red Hat npm packages compromised to steal developer credentials

    kirklandc008@gmail.comBy kirklandc008@gmail.comJune 2, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Red Hat
    Share
    Facebook Twitter LinkedIn Pinterest Email

    More than 30 npm packages under Red Hat’s ‘@redhat-cloud-services’ namespace were compromised in a supply-chain attack that distributed a new variant of the Shai-Hulud credential-stealing malware, dubbed “Miasma.”

    The incident was discovered by security firms Aikido and OX Security, which found dozens of package versions backdoored with malware designed to steal developer credentials, cloud secrets, SSH keys, CI/CD tokens, and other sensitive information.

    According to Aikido, the compromised packages receive roughly 117,000 weekly downloads.

    In a statement shared with BleepingComputer, Red Hat said it removed the affected packages after becoming aware of the incident and that the compromise was limited to internal development tooling.

    “Red Hat is aware of security reports regarding certain npm packages within our development tooling ecosystem. We immediately initiated an investigation and removed the packages from the npm registry,” Red Hat told BleepingComputer.

    “The packages are strictly limited to internal development, and the malicious code was never published for customer consumption via the console.redhat.com system. While our investigation is ongoing, we have not identified any impact to customer or partner environments or Red Hat production systems.”

    The company says it is continuing to investigate the incident, but did not answer our questions about how the account was compromised.

    Red Hat packages backdoored through GitHub compromise

    According to Aikido, the attackers allegedly compromised a Red Hat employee’s GitHub account and used it to push malicious commits directly to multiple repositories.

    Those commits added a GitHub Actions workflow and a script that abused npm’s publishing mechanism to release backdoored packages.

    “When the workflow runs, it installs Bun and executes _index.js, passing it a list of target packages via the OIDC_PACKAGES environment variable,” explains Aikido.

    “The script uses the id-token: write permission to request a short-lived OIDC token from GitHub, then uses that token to authenticate directly with npm’s trusted publishing endpoint and publish backdoored versions of every package in the list.”

    These compromised packages contained a malicious ‘preinstall script that automatically executed a heavily obfuscated malicious index.js file when developers installed the packages.


    “scripts”: {
    “preinstall”: “node index.js”
    }

    According to Aikido, the ‘index.js’ payload was approximately 4.2 MB in size, and is used to steal GitHub Actions secrets, AWS credentials, Google Cloud credentials, Azure service principal credentials, HashiCorp Vault tokens, Kubernetes service account tokens, npm and PyPI publishing tokens, SSH keys, Docker credentials, GPG keys, and `.env` files.

    Aikido says 32 packages and 96 package versions were affected by the compromise, including numerous client libraries maintained under the `@redhat-cloud-services` namespace.

    Organizations that installed any affected versions are advised to rotate all credentials, secrets, and tokens utilized by code on the infected device immediately.

    Miasma appears to be a new Shai-Hulud variant

    Over the past couple of months, there have been numerous supply chain attacks utilizing a Shai-Hulud malware to steal credentials and spread to other projects.

    These attacks have impacted well-known projects, including Bitwarden, SAP, Mistral, TanStack, OpenAI, and GitHub.

    In May, the TeamPCP threat group publicly released the source code for its Mini Shai-Hulud malware framework, making the malware available to other threat actors.

    Researchers say the malware used in the Red Hat compromise shares many similarities with Mini Shai-Hulud, but now utilizes the “Miasma: The Spreading Blight” string as comments in compromised GitHub repositories.

    Miasma-compromised repositories on GitHub

    While the malware resembles TeamPCP’s Mini Shai-Hulud, it is unclear whether the campaign was conducted by that threat actor or by another threat actor that modified the leaked malware source code.

    OX Security says the malware retains the same credential-stealing functionality as Mini Shai-Hulud but adds additional obfuscation layers, multi-stage payload delivery mechanisms, and enhanced data theft and credential-harvesting features.

    At the time of this writing, 309 GitHub repositories have been compromised by the Miasma malware campaign.

    Automated pentesting tools deliver real value, but they were built to answer one question: can an attacker move through the network? They were not built to test whether your controls block threats, your detection rules fire, or your cloud configs hold.

    This guide covers the 6 surfaces you actually need to validate.

    Download Now

    compromised credentials developer HAT npm packages Red steal
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Proving what a military AI model will do is the real problem

    June 15, 2026

    Phone battery draining fast? Malware is one of 8 possible factors – how to tell for sure

    June 15, 2026

    Laduora Duo 4-in-1 Red Light Therapy Scalp and Hair Care Device Review: Custom Goals

    June 15, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views

    Anthropic’s Mythos AI Uncovered Serious Security Holes in Every Major OS and Browser

    April 10, 20262 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • 6 Windhawk mods that make Windows 11 behave like it should
    • Why I designed Charlotte Tilbury Beauty as a technology company
    • Nintendo’s Switch 2 price is increasing to AU$769.95 come Sep 1 — which makes this AU$629 deal for EOFY all the more tempting
    • Here's what Jeff Bezos' new startup Prometheus will do
    • Berlin’s Qorelo raises €3 million five months after launch to tackle SAP’s 2027 transformation crunch

    6 Windhawk mods that make Windows 11 behave like it should

    June 15, 2026

    Why I designed Charlotte Tilbury Beauty as a technology company

    June 15, 2026

    Nintendo’s Switch 2 price is increasing to AU$769.95 come Sep 1 — which makes this AU$629 deal for EOFY all the more tempting

    June 15, 2026

    Here's what Jeff Bezos' new startup Prometheus will do

    June 15, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.