logo

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

ID: a0ee1a97-06fb-5c5d-b6d8-5dbd71aa91cb

STIX ID: report--a0ee1a97-06fb-5c5d-b6d8-5dbd71aa91cb

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-06-01

Date Updated: 2026-06-03

Author: [email protected] (The Hacker News)

...
...

A supply‑chain campaign named Miasma injected obfuscated preinstall hooks into multiple @redhat-cloud-services npm packages to harvest GitHub Actions secrets, npm tokens, cloud credentials, SSH/Git keys and other sensitive files, exfiltrating encrypted data to api.anthropic.com:443/v1/api with GitHub used as a fallback and committing artifacts labelled "Miasma:The Spreading Blight"; the malware also includes developer-tool and CI persistence mechanisms and worm-like propagation capabilities, with evidence pointing to a Red Hat GitHub account compromise as patient zero and activity observed since late May 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.