Red Hat removes 32 compromised packages after GitHub account breach led to malware distribution
By
Alexander Martin
An everything bagel for the brain. Substantive, layered, well-seasoned.
Summary
Red Hat removed 32 compromised packages from its software distribution pipeline after attackers used a stolen GitHub account to push credential-stealing malware to developers. The malicious packages were downloaded approximately 117,000 times per week. Red Hat stated that based on current findings, no customer action is required. The attack involved a variant of the Mini Shai-Hulud self-propagating worm.
Key quotes
· 3 pulledRed Hat pulled dozens of packages from its software distribution pipeline on Monday after attackers used a compromised GitHub account to distribute credential-stealing malware to developers.
According to the company's own preliminary analysis, a compromised GitHub account was used to push the malicious code out to customers, hitting 32 packages downloaded roughly 117,000 times a week.
Red Hat said it had since removed the affected packages and that 'based on current findings, no actions from customers are required.'
You might also wanna read
NPM Vulnerability Allows 126 Malicious Packages to Be Downloaded 86,000+ Times
Security researchers have discovered a major vulnerability in NPM (Node Package Manager) that allows attackers to distribute malicious packa
arstechnica.com·7mo agoMultiple @redhat-cloud-services npm packages compromised in supply chain attack
Multiple npm packages under the @redhat-cloud-services scope have been compromised with malicious releases. The affected packages include @r
317 npm Packages Compromised in Mini Shai-Hulud Supply Chain Attack
A major npm supply chain attack occurred on May 19, 2026, when the npm account of maintainer "atool" was compromised. The attacker published
Major NPM Supply Chain Attack: Over 1,000 Packages Infected via Fake Bun Runtime
A major cybersecurity incident occurred where over 1,000 NPM packages and 27,000+ GitHub repositories were infected within hours via a fake
Major NPM Supply Chain Attack: @ctrl/tinycolor and 40+ Packages Compromised with Self-Propagating Malware
A sophisticated supply chain attack has compromised the popular @ctrl/tinycolor NPM package (with over 2 million weekly downloads) along wit
Nx Build Kit Security Breach: Malware Steals Wallets and Credentials via GitHub Repositories
A security breach has been discovered in the popular Nx build kit where malicious post-install commands create unauthorized repositories nam
