Skip to content

Red Hat npm packages compromised in credential‑stealing supply‑chain attack

techJun 2, 2026138

Thirty-two packages in the redhat-cloud-services npm scope were backdoored with a credential-stealing worm called Miasma. Attackers used a compromised Red Hat employee GitHub account and stolen OIDC tokens to publish malicious package versions that execute at install time. The worm steals GitHub, npm, cloud, Kubernetes, Vault, SSH, and Git credentials, encrypts them, exfiltrates the data, and self-propagates across repositories. Organizations using those packages must audit dependencies, revoke exposed tokens, and rotate affected credentials because a single compromised CI trust enabled rapid supply-chain spread.

3 sources