Microsoft Threat Intelligence has uncovered a sophisticated supply chain attack targeting 32 npm packages under the @redhat-cloud-services scope, resulting in widespread credential theft and unauthorized system access.
Key Points
- Attackers compromised the RedHatInsights CI/CD pipeline to inject malicious code into over 90 versions of legitimate npm packages.
- The malware uses a multi-stage dropper to download the Bun JavaScript runtime, enabling cross-platform execution on Linux, macOS, and Windows.
- Stolen data includes credentials for GitHub, AWS, Azure, GCP, HashiCorp Vault, and Kubernetes, alongside SSH keys and browser wallet information.
- The payload scrapes GitHub Actions runner memory for secrets and uses forged SLSA provenance signatures to facilitate further downstream propagation.
- A destructive "tripwire" mechanism can wipe a victim's home directory if the malware detects interference with its planted decoy tokens.