Multiple @redhat-cloud-services npm packages compromised in supply chain attack
By
sailikhith-stepsecurity
Recycled flavour. You've tasted this bagel before.
Summary
Multiple npm packages under the @redhat-cloud-services scope have been compromised with malicious releases. The affected packages include @redhat-cloud-services/chrome, compliance-client, config-manager-client, entitlements-client, eslint-config-redhat-cloud-services, frontend-components, and several others. The security incident was reported by StepSecurity, highlighting a supply chain attack targeting Red Hat's cloud services npm ecosystem.
Key quotes
· 3 pulledMultiple @redhat-cloud-services npm packages have been compromised with malicious releases.
Affected packages include @redhat-cloud-services/chrome, compliance-client, config-manager-client, and several frontend-components packages.
The security incident was reported via StepSecurity's security feed and blog.
You might also wanna read
176 malicious npm packages used dependency confusion to target internal dependencies and steal credentials
Sonatype researchers uncovered a campaign involving 176 malicious npm packages using a dependency confusion attack strategy. Attackers publi
Postmortem: TanStack npm supply-chain compromise via GitHub Actions exploitation
On May 11, 2026, an attacker exploited a chain of vulnerabilities — including the pull_request_target "Pwn Request" pattern, GitHub Actions
Supply Chain Attack Compromises @ctrl/tinycolor npm Package, Affects 40+ Packages
A malicious update to the popular npm package @ctrl/tinycolor (2.2M weekly downloads) was detected as part of a broader supply chain attack
Suspicious hidden message discovered in jqwik testing library 1.10.0
A developer reports discovering a suspicious string in the jqwik testing library (version 1.10.0) that appears during Maven test runs. The s
Anthropic Releases Free Security Plugin for Claude Code Terminal to Detect Vulnerabilities
Anthropic has released a free security-guidance plugin for its Claude Code terminal tool that autonomously reviews code edits, model outputs
cybersecuritynews.com·15h agowolfCOSE: A Lightweight COSE + CBOR Library for Embedded Systems with PQC and FIPS 140-3 Support
wolfCOSE is a lightweight C library implementing CBOR (RFC 8949) and COSE (RFC 9052/9053) for embedded systems, using wolfSSL as the crypto
