Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Red Hat npm packages compromised to steal developer credentials

0
Medium
Malware
Published: Mon Jun 01 2026 (06/01/2026, 21:38:29 UTC)
Source: Bleeping Computer

Description

More than 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were compromised in a supply-chain attack that distributed a new variant of the Shai-Hulud credential-stealing malware, dubbed "Miasma." [...]

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/01/2026, 21:48:43 UTC

Technical Analysis

A supply-chain attack compromised over 30 npm packages in Red Hat's '@redhat-cloud-services' namespace by injecting a new variant of the Shai-Hulud malware named "Miasma." Attackers gained access to a Red Hat employee's GitHub account, pushed malicious commits that added a GitHub Actions workflow and scripts to publish backdoored package versions. These packages contained a preinstall script executing a heavily obfuscated payload that steals a wide range of credentials and secrets, including GitHub Actions secrets, cloud provider credentials, SSH keys, and tokens. Red Hat removed the compromised packages after discovery and confirmed the compromise was limited to internal development tooling with no detected impact on customer environments or production systems. The malware shares similarities with the Mini Shai-Hulud framework but includes enhanced obfuscation and data theft capabilities. At the time of reporting, 32 packages and 96 versions were affected, with approximately 117,000 weekly downloads.

Potential Impact

The malware steals sensitive developer credentials and secrets such as cloud provider credentials, SSH keys, CI/CD tokens, and other authentication tokens, potentially enabling attackers to access and compromise developer environments and cloud resources. However, Red Hat confirmed no impact on customer or partner environments or production systems. The compromised packages were limited to internal development tooling and have been removed from the npm registry. Organizations that installed affected package versions risk credential exposure and should assume compromise of secrets used on infected devices.

Mitigation Recommendations

Red Hat has removed the affected packages from the npm registry and is investigating the incident. The compromise was limited to internal development tooling, and no impact to customer or production systems has been identified. Organizations that installed any affected package versions should immediately rotate all credentials, secrets, and tokens used on the infected devices. Users should monitor Red Hat's official advisories for updates and remediation guidance. Patch status is not yet confirmed; consult vendor advisories for current remediation information.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/red-hat-npm-packages-compromised-to-steal-developer-credentials/","fetched":true,"fetchedAt":"2026-06-01T21:48:35.647Z","wordCount":979}

Threat ID: 6a1dfe33e29bf47b504b8ccc

Added to database: 6/1/2026, 9:48:35 PM

Last enriched: 6/1/2026, 9:48:43 PM

Last updated: 6/2/2026, 6:49:08 AM

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses