Close Menu
  • Start
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Miasma supply chain attack compromises Red Hat npm packages with credential-stealing worm

Human files are published

DuckDuckGo eases access to ‘AI-free’ search engine as traffic soars

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
Fyself News
  • Start
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Miasma supply chain attack compromises Red Hat npm packages with credential-stealing worm
Identity

Miasma supply chain attack compromises Red Hat npm packages with credential-stealing worm

By June 1, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, compromised the @redhat-cloud-services package to steal credentials and sensitive information from developer machines and distribute a self-propagating worm.

“This is effectively a Mini Shai-Hulud campaign, using the same core tactics of execution at install, credential collection, CI/CD targeting, encrypted exfiltration, and potential downstream propagation,” Socket said.

It is currently unclear exactly who is behind the campaign, given that notorious cybercrime group TeamPCP has open-sourced attack tools related to the Shai-Hulud worm, which opens up opportunities for other threat actors to carry out similar attacks and makes it difficult to identify a clear attacker.

Some of the names of the affected packages are listed below.

@redhat-cloud-services/vulnerabilities-client @redhat-cloud-services/tsc-transform-imports @redhat-cloud-services/topological-inventory-client @redhat-cloud-services/sources-client @redhat-cloud-services/rule-components @redhat-cloud-services/remediations-client @redhat-cloud-services/rbac-client

According to analysis by Aikido Security, JFrog, Microsoft, OX Security, SafeDep, StepSecurity, and Wiz, npm packages contain obfuscated preinstallation hooks designed to collect GitHub Actions secrets, npm tokens, cloud credentials, Kubernetes and Vault materials, SSH keys, Git credentials, and other sensitive files.

As observed in previous waves of Mini Shai-Hulud, the malware also contains encrypted exfiltration logic that sends data to ‘api.anthropic’.[.]com:443/v1/api” and uses GitHub as a fallback mechanism. This represents an attempt by an attacker to steal credentials and weaponize them to further contaminate the software supply chain.

“We commit the encrypted result envelope via the GitHub API,” Socket said. “The commit message can include IfYouInvalidateThisTokenItWillNukeTheComputerOfTheOwner:.”

Another notable step taken by this malware is to avoid running on Russian systems. This is a pattern also observed in the GlassWorm supply chain campaign.

“For npm, the payload calls the OIDC token exchange and whoami endpoint, repackages the tarball (updateTarball, package-updated.tgz), and signs the artifact through Sigstore,” SafeDep said. “Stolen credentials were leaked to public GitHub repositories created by the attackers, each with the description Miasma: The Spreading Blight.”

The first commit containing the string “Miasma: The Spreading Blight” appeared on May 29, 2026, indicating that the variant has been active or that threat actors have begun testing it since then, OX Security noted.

Regarding GitHub, the malware enumerates the repositories that the token can write to, reads action.yml/action.yaml via GraphQL, and commits the workflow through the createCommitOnBranch mutation so that the commit appears as a verified signed change. Other actions performed by the malware are listed below.

Bind mount the host /etc/sudoers.d and attempt privilege escalation by starting a container that grants passwordless sudo to the CI runner. Check endpoint protection with CrowdStrike, SentinelOne, Carbon Black, and StepSecurity Harden-Runner before initiating malicious actions. Inject a SessionStart hook in Anthropic Claude Code and establish persistence by injecting a task.json with Microsoft’s “runOn”: “folderOpen”. Enable Visual Studio Code projects to launch malware automatically every session

“One of the main changes in this new variant is the addition of a new data collector focused on cloud identities,” Wiz researchers said. “Specifically, we added a GCP and Azure ID collector that collects all identities that an infected machine has access to. While previous versions of the malware were primarily focused on extracting secrets from these environments, this variant suggests that the attackers are focused on gaining and leveraging access to the cloud itself.”

Unlike previous versions, this malware has also been found to generate a uniquely encrypted payload for each infection, making detection and version tracking much more difficult.

Evidence suggests that the Red Hat employee’s GitHub account was compromised by Patient Zero, which was used to inject payloads into these packages. The compromised account allegedly pushed malicious orphan commits to two RedHatInsights repositories, bypassing code reviews.

We recommend that you isolate hosts that have installed the affected version, remove malicious versions, rotate exposed credentials, check for signs of suspicious GitHub or npm activity, and audit your environment for persistence artifacts with changes to configuration files (~/.claude/settings.json, .vscode/tasks.json, .github/workflows/codeql.yml, .github/setup.js). Apply strong access controls.

“Uninstalling npm packages or removing node_modules should not be considered sufficient cleanup as this malware includes background execution and potential developer tools persistence mechanisms,” Socket explained.

“For CI/CD systems, pause execution of affected workflows, disable build artifacts generated during the exposure period, and check to see if any releases, container images, npm packages, or deployment artifacts were created after the malicious package was installed.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleHuman files are published

Related Posts

New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More

June 1, 2026

Dragonweave has landed in the Czech Republic and Taiwan

June 1, 2026

Why MSPs are moving beyond vCISO tools

June 1, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Miasma supply chain attack compromises Red Hat npm packages with credential-stealing worm

Human files are published

DuckDuckGo eases access to ‘AI-free’ search engine as traffic soars

New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.