Close Menu
    What's Hot

    You Paid for a Specific Seat on a Flight. The Airline…

    A Trump Deal With Iran Could Spell Trouble for Israel’s Netanyahu

    Mills Reminds Maine Voters She’s ‘Still on the Ballot’ for Senate Amid Platner Controversy

    Facebook X (Twitter) Instagram
    Trending
    • You Paid for a Specific Seat on a Flight. The Airline…
    • A Trump Deal With Iran Could Spell Trouble for Israel’s Netanyahu
    • Mills Reminds Maine Voters She’s ‘Still on the Ballot’ for Senate Amid Platner Controversy
    • Who watches the watch parties?
    • This Food Delivery Service Is Hiring a Role for $200,000 a Year
    • The Hundred: Jamie Overton, Davina Perrin, Tom Curran among Hundred stars launching new trophy and team kits | Cricket News
    • Browns trade Myles Garrett to Rams: Seven big questions
    • Pebblebee’s Halo can help track lost items and keep you safe, and it’s on sale for $50
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

    adminBy adminJune 1, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

    A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a self-propagating worm.

    “This is effectively a Mini Shai-Hulud campaign: it uses the same core tactics of install-time execution, credential harvesting, CI/CD targeting, encrypted exfiltration, and potential downstream propagation,” Socket said.

    Exactly who is behind the attack activity is presently unknown given that TeamPCP, an infamous cybercrime group, has open-sourced the attack tools linked to the Shai-Hulud worm, opening the door for other threat actors to pull off similar attacks and making definitive attribution harder.

    The names of some of the affected packages are listed below –

    • @redhat-cloud-services/vulnerabilities-client
    • @redhat-cloud-services/tsc-transform-imports
    • @redhat-cloud-services/topological-inventory-client
    • @redhat-cloud-services/sources-client
    • @redhat-cloud-services/rule-components
    • @redhat-cloud-services/remediations-client
    • @redhat-cloud-services/rbac-client

    Per analyses from Aikido Security, JFrog, Microsoft, OX Security, SafeDep, StepSecurity, and Wiz, the npm packages contain an obfuscated preinstall hook that’s designed to collect GitHub Actions secrets, npm tokens, cloud credentials, Kubernetes and Vault material, SSH keys, Git credentials, and other sensitive files.

    Cybersecurity

    Like observed in prior Mini Shai-Hulud waves, the malware also contains encrypted exfiltration logic that transmits the data to “api.anthropic[.]com:443/v1/api” and uses GitHub as a fallback mechanism. This indicates attempts made by the attacker to both steal credentials and weaponize them to further poison the software supply chain.

    “It commits the encrypted result envelope through the GitHub API,” Socket said. “The commit message can include: IfYouInvalidateThisTokenItWillNukeTheComputerOfTheOwner:.”

    Another noteworthy step carried out by the malware is to avoid execution on Russian-language systems, a pattern also observed in the GlassWorm supply chain campaigns.

    “For npm, the payload calls the OIDC token exchange and whoami endpoints, repackages a tarball (updateTarball, package-updated.tgz), and signs the artifact through Sigstore,” SafeDep said. “Stolen credentials exfiltrate to attacker-created public GitHub repositories, each carrying the description Miasma: The Spreading Blight.”

    The first commit containing the “Miasma: The Spreading Blight” string appeared on May 29, 2026, OX Security noted, indicating that either this variant was active since then, or the threat actor started testing around that time.

    As for GitHub, the malware enumerates repositories the token can write to, reads action.yml/action.yaml via GraphQL, and commits a workflow through the createCommitOnBranch mutation so that the commit appears as a verified, signed change. Other actions carried out by the malware are listed below –

    • Attempt privilege escalation by launching a container that bind-mounts the host /etc/sudoers.d and grants the CI runner passwordless sudo
    • Check for endpoint protection from CrowdStrike, SentinelOne, Carbon Black, and StepSecurity Harden-Runner before commencing the malicious actions
    • Establish persistence by injecting a SessionStart hook to Anthropic Claude Code and a tasks.json with “runOn”: “folderOpen” for Microsoft Visual Studio Code projects so that the malware is automatically launched during every session

    “One of the main changes in this new variant is the addition of new data collectors focused on cloud identities,” Wiz researchers said. “Specifically, collectors for GCP and Azure identities were added that collect all identities the infected machine has access to. While previous versions of the malware primarily focused on extracting secrets from these environments, this variant suggests an increased attacker focus on gaining and leveraging access to the cloud itself.

    Unlike previous versions, the malware has also been found to generate a uniquely encrypted payload for each infection, thereby making detection and version tracking significantly more challenging.

    Cybersecurity

    Evidence suggests that the compromise of a Red Hat employee’s GitHub account was the patient zero that was used to inject the payload into these packages. The compromised account is said to have pushed malicious orphan commits to two RedHatInsights repositories, bypassing code review.

    It’s recommended to isolate hosts that have installed the affected versions, remove the malicious versions, rotate exposed credentials, review for any signs of suspicious GitHub or npm activity, audit the environment for persistence artifacts that involve changes to configuration files (~/.claude/settings.json, .vscode/tasks.json, .github/workflows/codeql.yml, .github/setup.js), and enforce strong access controls.

    “Because the malware includes background execution and potential developer-tool persistence mechanisms, uninstalling the npm package or deleting node_modules should not be considered sufficient cleanup,” Socket explained.

    “For CI/CD systems, suspend affected workflow runs, invalidate build artifacts produced during the exposure window, and review whether any release, container image, npm package, or deployment artifact was created after the malicious package was installed.”

    attack Chain Compromises CredentialStealing hat Miasma npm Packages red Supply Worm
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous Article‘The smartest thing a celebrity has done’: Dua Lipa turns her jetsetter meme into a Google Maps collab
    Next Article Pebblebee’s Halo can help track lost items and keep you safe, and it’s on sale for $50
    admin
    • Website

    Related Posts

    Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts – Krebs on Security

    June 1, 2026

    OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack

    June 1, 2026

    Netanyahu Orders Israeli Military to Attack Beirut Suburbs

    June 1, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    You Paid for a Specific Seat on a Flight. The Airline…

    A Trump Deal With Iran Could Spell Trouble for Israel’s Netanyahu

    Mills Reminds Maine Voters She’s ‘Still on the Ballot’ for Senate Amid Platner Controversy

    Who watches the watch parties?

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by