Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm
ID: d65ab580-464a-5db2-9dd3-82f99a742ca0
STIX ID: report--d65ab580-464a-5db2-9dd3-82f99a742ca0
Feed Name: Aikido Security's Blog
On June 1, 2026, multiple official @redhat-cloud-services npm packages were compromised via a malicious GitHub Actions OIDC workflow that published backdoored package versions containing a credential‑stealing worm dubbed "Miasma" (a Mini Shai‑Hulud variant); 96 versions across 32 packages were affected and cumulatively downloaded ~116,991 times/week, the payload exfiltrates a broad range of CI/cloud/dev credentials and includes preinstall hooks and an obfuscated 4.2 MB index.js — affected consumers should rotate all CI secrets, cloud credentials, SSH keys, and publish tokens immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
