BleepingComputerWednesday · June 3, 2026FREE

Red Hat npm packages compromised to steal developer credentials

supply-chainnpmmalwarered-hat

More than 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were compromised in a supply-chain attack that distributed a new variant of the Shai-Hulud credential-stealing malware, dubbed 'Miasma.' The malicious packages were published to the npm registry and designed to steal developer credentials, including SSH keys, AWS tokens, and other sensitive information. The attack was discovered by security researchers who noted that the compromised packages were downloaded thousands of times before being taken down. Red Hat has removed the affected packages and is investigating the incident. Developers who have used these packages are advised to rotate any credentials that may have been exposed and to audit their systems for signs of compromise.

// why it matters

Compromised packages can steal developer credentials, leading to unauthorized access to critical infrastructure.

Sources

Primary · BleepingComputerMirror · BleepingComputerMirror · The Hacker NewsMirror · LobstersMirror · Hacker NewsMirror · DEV Community
▸ Read original at bleepingcomputer.com

Like this? Get the next digest.

Red Hat npm packages compromised to steal developer credentials — aigest.dev