Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign
ID: c6a89d7f-f15f-56f6-a200-31b680665989
STIX ID: report--c6a89d7f-f15f-56f6-a200-31b680665989
Feed Name: Microsoft Security
Date Published: 2026-06-03
Date Updated: 2026-06-03
Author: Microsoft Defender Security Research Team
Microsoft Threat Intelligence discovered a large-scale npm supply-chain attack in which 32 packages under the @redhat-cloud-services scope were trojanized via a compromised CI/CD publishing workflow; the malicious preinstall hook executed an obfuscated dropper that fetched the Bun runtime and deployed a cross-platform credential-harvesting and propagation payload that scrapes CI runner memory, steals cloud and repo credentials, republishes poisoned packages with forged provenance, and includes a destructive wiper.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
