logo

Red Hat hit by npm supply‑chain attack - here's how to stay safe

ID: 310b233e-186e-5fe3-80f0-5b2a8695850a

STIX ID: report--310b233e-186e-5fe3-80f0-5b2a8695850a

Feed Name: ZDNet Security

Threat Score
75/100

Date Published: 2026-06-03

Date Updated: 2026-06-04

...
...

Red Hat's @redhat-cloud-services npm namespace was compromised when attackers used a compromised GitHub/CI pipeline to inject obfuscated preinstall hooks into 32 packages (96 versions), distributing a wormable credential-stealing payload (a Miasma/Mini Shai-Hulud variant) that exfiltrates GitHub, cloud, CI/CD, SSH, and secret-manager credentials and self-propagates by republishing infected packages; Red Hat removed the packages and reports no customer production impact, but organizations that pulled the affected versions should rotate secrets, audit activity, and rebuild contaminated environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.