Skip to main content
See every side of every news story
Published loading...Updated

Dozens of Red Hat packages backdoored through its offical NPM channel

  • On Monday, attackers compromised a Red Hat employee's GitHub account to distribute npm packages infected with a new malware variant dubbed "Miasma." The IBM-owned software firm's compromised account pushed malicious code to multiple repositories.
  • This attack utilizes a derivative of the Shai-Hulud worm, which the TeamPCP cybercriminal group open-sourced last month, enabling other threat actors to modify the framework for credential theft operations.
  • Security firm Aikido identified 32 packages and 96 versions affected, which receive around 80,000 weekly downloads; the malicious 4.2 MB payload automatically executes during npm installation to steal cloud credentials and tokens.
  • Red Hat immediately removed the packages from the npm registry and stated no customer or production systems were impacted, though the firm advises all users to rotate credentials, secrets, and tokens immediately.
  • Security firm Wiz warns that Miasma represents an increased attacker focus on cloud infrastructure; the variant adds advanced obfuscation and targets Microsoft Azure and Google Cloud identities beyond traditional secret theft.
Insights by Ground AI

20 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

slashdot.org broke the news on Monday, June 1, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal