logo

Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign

ID: c6a89d7f-f15f-56f6-a200-31b680665989

STIX ID: report--c6a89d7f-f15f-56f6-a200-31b680665989

Feed Name: Microsoft Security

Threat Score
92/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Microsoft Defender Security Research Team

...
...

Microsoft Threat Intelligence discovered a large-scale npm supply-chain attack in which 32 packages under the @redhat-cloud-services scope were trojanized via a compromised CI/CD publishing workflow; the malicious preinstall hook executed an obfuscated dropper that fetched the Bun runtime and deployed a cross-platform credential-harvesting and propagation payload that scrapes CI runner memory, steals cloud and repo credentials, republishes poisoned packages with forged provenance, and includes a destructive wiper.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.