Red Hat Confirms Supply Chain Breach Impacting @redhat-cloud-services npm Packages
ID: 83669707-b626-576e-a71f-919a3f75c4d0
STIX ID: report--83669707-b626-576e-a71f-919a3f75c4d0
Feed Name: GBHackers
Red Hat disclosed a supply-chain breach caused by a compromised GitHub account that introduced malicious commits into frontend libraries under the @redhat-cloud-services npm namespace; the malicious package versions were published to npm and subsequently removed. Red Hat is investigating whether those packages were incorporated into production or shipped products, currently reports no evidence of customer impact, and recommends auditing dependencies, monitoring build pipelines, and enforcing strong authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
