logo

Miasma Malware Targets Red Hat npm Packages in New Supply Chain Attack

ID: 7d6d57ae-e3f4-57c0-b062-48bdf8ed0306

STIX ID: report--7d6d57ae-e3f4-57c0-b062-48bdf8ed0306

Feed Name: The Cyber Express

Threat Score
85/100

Date Published: 2026-06-02

Date Updated: 2026-06-03

Author: Ashish Khaitan

...
...

Miasma is a software supply-chain campaign that injected malicious install-time code into multiple @redhat-cloud-services npm packages to steal credentials and secrets, exfiltrate data (to api.anthropic.com), and propagate via GitHub by abusing tokens and the createCommitOnBranch API to produce verified commits. The malware includes persistence in developer tools and CI/CD, privilege-escalation attempts, endpoint detection evasion, and investigators believe a compromised Red Hat GitHub account served as the initial entry point; researchers urge isolation, credential rotation, and thorough auditing of repositories, CI artifacts, and developer environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.