Red Hat npm supply chain attack compromises 32 packages with credential-stealing malware
Has the shape of a bagel but none of the steam.
Summary
A supply chain attack targeted Red Hat's npm namespace (@redhat-cloud-services), with 96 compromised versions across 32 packages backdoored with credential-stealing malware. Downloaded approximately 116,991 times per week, the malware was injected via a compromised GitHub account and executed through npm preinstall hooks. The malicious payload targeted secrets from npm, GitHub, AWS, and SSH environments, primarily affecting Red Hat developers and CI/CD systems. The affected packages were front-end libraries used in Red Hat product builds.
Key quotes
· 4 pulledDozens of packages in the @redhat-cloud-services npm namespace were backdoored with credential-stealing malware aimed at Red Hat developers and CI/CD systems.
Aikido reported 96 compromised versions across 32 packages, downloaded 116,991 times per week.
Red Hat said a compromised GitHub account injected malicious code into packages maintained in a Red Hat GitHub organization.
The malware executed through npm preinstall hooks during npm install, running an obfuscated index.js loader that downloaded and executed a payload to vacuum secrets from npm, GitHub, AWS, and SSH environments.
You might also wanna read
Multiple @redhat-cloud-services npm packages compromised in supply chain attack
Multiple npm packages under the @redhat-cloud-services scope have been compromised with malicious releases. The affected packages include @r
Major NPM Supply Chain Attack: Over 1,000 Packages Infected via Fake Bun Runtime
A major cybersecurity incident occurred where over 1,000 NPM packages and 27,000+ GitHub repositories were infected within hours via a fake
Major NPM Supply Chain Attack: @ctrl/tinycolor and 40+ Packages Compromised with Self-Propagating Malware
A sophisticated supply chain attack has compromised the popular @ctrl/tinycolor NPM package (with over 2 million weekly downloads) along wit
NPM Vulnerability Allows 126 Malicious Packages to Be Downloaded 86,000+ Times
Security researchers have discovered a major vulnerability in NPM (Node Package Manager) that allows attackers to distribute malicious packa
arstechnica.com·7mo agoNPM supply chain attack compromises popular packages, posing widespread security risk
A significant supply chain attack on the NPM package ecosystem compromised several popular packages, potentially allowing malicious code to
317 npm Packages Compromised in Mini Shai-Hulud Supply Chain Attack
A major npm supply chain attack occurred on May 19, 2026, when the npm account of maintainer "atool" was compromised. The attacker published
