logo

31 Red Hat npm packages backdoored in 72 seconds

ID: a65f282d-f66b-5992-9ae6-c68c44cdd645

STIX ID: report--a65f282d-f66b-5992-9ae6-c68c44cdd645

Feed Name: ReversingLabs Blog

Threat Score
90/100

Date Published: 2026-06-01

Date Updated: 2026-06-03

Author: RL Research Team

...
...

**Executive summary:** On June 1, 2026 ReversingLabs identified a scope-level compromise of the @redhat-cloud-services npm namespace in which an attacker automated the publication of 31 malicious package versions within a 72‑second window; each package included an identical modification (a preinstall script invoking an obfuscated index.js) that implements a three-layer payload (ROT‑N → AES‑128‑GCM → obfuscator.io) which downloads the bun runtime and executes a 634 KB credential‑stealing, worm‑capable payload — roughly 9.8 million cumulative downloads increase potential exposure; clean versions were later published but any build that ran npm install during the window should be treated as compromised and remediated per the report's recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.