AUTO-UPDATED

Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign

Microsoft Threat Intelligence has uncovered a sophisticated supply chain attack targeting 32 npm packages under the @redhat-cloud-services scope, resulting in widespread credential theft and unauthorized system access.

Key Points

  • Attackers compromised the RedHatInsights CI/CD pipeline to inject malicious code into over 90 versions of legitimate npm packages.
  • The malware uses a multi-stage dropper to download the Bun JavaScript runtime, enabling cross-platform execution on Linux, macOS, and Windows.
  • Stolen data includes credentials for GitHub, AWS, Azure, GCP, HashiCorp Vault, and Kubernetes, alongside SSH keys and browser wallet information.
  • The payload scrapes GitHub Actions runner memory for secrets and uses forged SLSA provenance signatures to facilitate further downstream propagation.
  • A destructive "tripwire" mechanism can wipe a victim's home directory if the malware detects interference with its planted decoy tokens.

Why it Matters

This incident highlights the severe risks posed by compromised CI/CD pipelines, which can turn trusted software updates into vehicles for large-scale credential harvesting and worm-like propagation. By forging provenance metadata, the attackers successfully eroded trust in supply chain security frameworks, necessitating urgent audits of developer environments and automated build systems.
Microsoft.com Published by Microsoft Defender Security Research Team
Read original