logo

Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm

ID: d65ab580-464a-5db2-9dd3-82f99a742ca0

STIX ID: report--d65ab580-464a-5db2-9dd3-82f99a742ca0

Feed Name: Aikido Security's Blog

Threat Score
88/100

Date Published: 2026-06-01

Date Updated: 2026-07-24

...
...

On June 1, 2026, multiple official @redhat-cloud-services npm packages were compromised via a malicious GitHub Actions OIDC workflow that published backdoored package versions containing a credential‑stealing worm dubbed "Miasma" (a Mini Shai‑Hulud variant); 96 versions across 32 packages were affected and cumulatively downloaded ~116,991 times/week, the payload exfiltrates a broad range of CI/cloud/dev credentials and includes preinstall hooks and an obfuscated 4.2 MB index.js — affected consumers should rotate all CI secrets, cloud credentials, SSH keys, and publish tokens immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.