SECURITYBLEEPING COMPUTER
Red Hat npm packages compromised to steal developer credentials
More than 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were compromised in a supply-chain attack that distributed a new variant of the Shai-Hulud credential-stealing malware, dubbed 'Miasma'.
Mentioned
Related Signal
Adjacent reporting
- Official SAP npm packages compromised to steal credentials
- SAP npm Packages Compromised by “Mini Shai-Hulud” Credential-Stealing Malware
- Bitwarden CLI npm package compromised to steal developer credentials
- TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack
- Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
- Popular node-ipc npm package compromised to steal credentials