More than 30 official Red Hat Cloud Services npm packages were compromised by the Miasma malware, which steals sensitive developer credentials through a malicious automated preinstall script.
Key Points
- Aikido Security identified over 30 compromised Red Hat Cloud Services packages containing the Miasma credential-stealing worm.
- The attack originated from a compromised GitHub Actions CI/CD pipeline rather than a stolen npm token.
- Malicious code executes automatically upon installation via a hidden 4.2 MB obfuscated payload in the package.json file.
- The malware targets AWS, GCP, and Azure credentials, alongside SSH keys, Kubernetes tokens, and various CI/CD secrets.
- Users who installed affected packages since June 1, 2026, are advised to rotate all cloud and development environment credentials immediately.