Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

A new Mini Shai-Hulud supply chain campaign, codenamed Miasma, has compromised multiple @redhat-cloud-services npm packages to steal credentials and secrets from developer machines while also planting a self-propagating worm. Researchers say the malware uses install-time execution, encrypted exfiltration, CI/CD targeting, and persistence tricks, with evidence linking the intrusion to a compromised Red Hat employee GitHub account. #Miasma #ShaiHulud #RedHat #GitHub

Keypoints

  • The Miasma campaign compromised several @redhat-cloud-services npm packages.
  • The malware steals GitHub, npm, cloud, Kubernetes, Vault, SSH, and Git credentials.
  • It uses encrypted exfiltration and can spread through poisoned software supply chains.
  • The payload targets GitHub Actions, CI/CD workflows, and developer tools for persistence.
  • Investigators linked the initial compromise to a Red Hat employee GitHub account.

Read More: https://thehackernews.com/2026/06/miasma-supply-chain-attack-compromises.html