AUTO-UPDATED

Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm

More than 30 official Red Hat Cloud Services npm packages were compromised by the Miasma malware, which steals sensitive developer credentials through a malicious automated preinstall script.

Key Points

  • Aikido Security identified over 30 compromised Red Hat Cloud Services packages containing the Miasma credential-stealing worm.
  • The attack originated from a compromised GitHub Actions CI/CD pipeline rather than a stolen npm token.
  • Malicious code executes automatically upon installation via a hidden 4.2 MB obfuscated payload in the package.json file.
  • The malware targets AWS, GCP, and Azure credentials, alongside SSH keys, Kubernetes tokens, and various CI/CD secrets.
  • Users who installed affected packages since June 1, 2026, are advised to rotate all cloud and development environment credentials immediately.

Why it Matters

This supply-chain attack highlights the critical vulnerability of automated CI/CD pipelines when used to publish official software packages. Organizations must now treat all development environment secrets as compromised if they have utilized these specific Red Hat packages, underscoring the need for rigorous dependency auditing.
Slashdot.org Published by BeauHD
Read original