logo

Miasma Malware Hits 32 Red Hat Packages via Compromised GitHub Account

ID: d2bc59a8-393e-5c96-a155-861c484999f0

STIX ID: report--d2bc59a8-393e-5c96-a155-861c484999f0

Feed Name: HackRead

Threat Score
90/100

Date Published: 2026-06-05

Date Updated: 2026-06-06

Author: Deeba Ahmed

...
...

On 1 June 2026 security researchers disclosed a major npm supply-chain compromise: attackers used a compromised Red Hat developer GitHub account and minimal GitHub Actions workflows requesting short‑lived OIDC tokens to publish 96 malicious package versions across ~32 packages in the @redhat-cloud-services namespace. The backdoored packages contained a worm/credential‑stealer named Miasma that exfiltrates cloud and SSH keys and self‑propagates by republishing packages the compromised identity can modify; most malicious versions were quickly revoked and vendors advised immediate credential rotation, checking lockfiles, and blocking install scripts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.