{"id":261292,"date":"2026-06-01T13:40:00","date_gmt":"2026-06-01T17:40:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/06\/01\/miasma-supply-chain-attack-compromises-red-hat-npm-packages-with-credential-stealing-worm\/"},"modified":"2026-06-01T14:50:09","modified_gmt":"2026-06-01T18:50:09","slug":"miasma-supply-chain-attack-compromises-red-hat-npm-packages-with-credential-stealing-worm","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/06\/01\/miasma-supply-chain-attack-compromises-red-hat-npm-packages-with-credential-stealing-worm\/","title":{"rendered":"Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/06\/miasma-supply-chain-attack-compromises.html\">Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/06\/miasma-supply-chain-attack-compromises.html\">https:\/\/thehackernews.com\/2026\/06\/miasma-supply-chain-attack-compromises.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-06-01 13:40:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p>A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a self-propagating worm.<\/p>\n<p>&#8220;This is effectively a Mini Shai-Hulud campaign: it uses the same core tactics of install-time execution, credential harvesting, CI\/CD targeting, encrypted exfiltration, and potential downstream propagation,&#8221; Socket said.<\/p>\n<p>Exactly who is behind the attack activity is presently unknown given that TeamPCP, an infamous cybercrime group, has open-sourced the attack tools linked to the Shai-Hulud worm, opening the door for other threat actors to pull off similar attacks and making definitive attribution harder.<\/p>\n<p>The names of some of the affected packages are listed below &#8211;<\/p>\n<ul>\n<li>@redhat-cloud-services\/vulnerabilities-client<\/li>\n<li>@redhat-cloud-services\/tsc-transform-imports<\/li>\n<li>@redhat-cloud-services\/topological-inventory-client<\/li>\n<li>@redhat-cloud-services\/sources-client<\/li>\n<li>@redhat-cloud-services\/rule-components<\/li>\n<li>@redhat-cloud-services\/remediations-client<\/li>\n<li>@redhat-cloud-services\/rbac-client<\/li>\n<\/ul>\n<p>Per analyses from Aikido Security, JFrog, Microsoft, OX Security, SafeDep, StepSecurity, and Wiz, the npm packages contain an obfuscated preinstall hook that&#8217;s designed to collect GitHub Actions secrets, npm tokens, cloud credentials, Kubernetes and Vault material, SSH keys, Git credentials, and other sensitive files.<\/p>\n<p>Like observed in prior Mini Shai-Hulud waves, the malware also contains encrypted exfiltration logic that transmits the data to &#8220;api.anthropic[.]com:443\/v1\/api&#8221; and uses GitHub as a fallback mechanism. This indicates attempts made by the attacker to both steal credentials and weaponize them to further poison the software supply chain.<\/p>\n<p>&#8220;It commits the encrypted result envelope through the GitHub API,&#8221; Socket said. &#8220;The commit message can include: IfYouInvalidateThisTokenItWillNukeTheComputerOfTheOwner:.&#8221;<\/p>\n<p><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"698\" data-original-width=\"746\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhORC_YvikOzAygGwJ1HFGJePm594z3zlUFKSKKdN0iltmsIOHeADbUCUXBQsuHx2wm0qYJWdbOQir9_OPLjMQdRCdtqF9Tgq_prOZU7hqDSOBca13vd2JC-7Cw7CSmyJhtKfWgDGA4w8jnNPyxoa6OSzoeevR7XDzBxTeuAJS4LkcgFqZfNWlWt2SbWX3b\/s1600\/ox.jpg\"\/><\/p>\n<p>Another noteworthy step carried out by the malware is to&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/06\/miasma-supply-chain-attack-compromises.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm https:\/\/thehackernews.com\/2026\/06\/miasma-supply-chain-attack-compromises.html Publish Date:&#8230;<\/p>\n","protected":false},"author":1,"featured_media":261293,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjOyc2NTiIl0XKOTZBsFh1bTPqNpVXfDhASWkCsYz17d-nbiWVKlxCzoq3WthMD8kMomrRPPOYLM-XRmSdtXNKAxtk1QLtmZH47y2RExMGohBaBDPkpFp2PteUgaA16VcCs7tK-ImqCiLnpqyLg8Pwp6cWE5d9QT2_v0-QBduT7ovYrs7WSZ9t1MnQJ4EuO\/s1600\/redhat.png","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[32],"class_list":["post-261292","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-malware"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/261292"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=261292"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/261292\/revisions"}],"predecessor-version":[{"id":261294,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/261292\/revisions\/261294"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/261293"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=261292"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=261292"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=261292"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}