TeamPCP? Or copycat malware dev?
Compromised npm packages targeted Red Hat cloud services, enabling credential theft and expanding supply chain risks.
Anyone who has downloaded affected Red Hat packages should investigate immediately.
Researchers have uncovered a new Shai-Hulud malware variant targeting Red Hat-related npm packages, spreading through software publishing ecosystems for persistence and credential theft.
32 Red Hat NPM packages compromised in 72-second attack; malware steals GitHub/npm tokens, cloud credentials impacting ~10M downloads. Supply chain attack escalation; immediate credential rotation and dependency audits critical for all JavaScript-using teams.
Die Managed Cloud Services von Red Hat waren das Ziel einer Lieferkettenattacke. Dahinter steckt ein Klon des npm-Wurms Mini Shai‑Hulud.
Miasma compromised @redhat-cloud-services npm packages, harvesting credentials and persisting in development tools. The worm escalates privileges, steals cloud identities, and propagates via GitHub—threatening CI/CD integrity and supply chains.
More than 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were compromised in a supply-chain attack that distributed a new variant of the Shai-Hulud credential-stealing malware, dubbed "Miasma."
More than 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were compromised in a supply-chain attack that distributed a new variant of the Shai-Hulud…
Researchers have uncovered a new Shai-Hulud malware variant targeting Red Hat-related npm packages, spreading through software publishing ecosystems for persistence and credential…
Hackers published 96 malicious versions across 32 Red Hat NPM packages in a supply chain attack similar to Mini Shai-Hulud.
A new supply-chain attack has infected 36 packages on the Node Package Manager (npm) index with infostealer malware called IronWorm.