All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.
First reported by Hacker News
Multiple @redhat-cloud-services npm packages compromised in supply chain attack

Red Hat npm supply chain attack compromises 32 packages with credential-stealing malware

4h ago· 1 min readenNews

Summary

A supply chain attack targeted Red Hat's npm namespace (@redhat-cloud-services), with 96 compromised versions across 32 packages backdoored with credential-stealing malware. Downloaded approximately 116,991 times per week, the malware was injected via a compromised GitHub account and executed through npm preinstall hooks. The malicious payload targeted secrets from npm, GitHub, AWS, and SSH environments, primarily affecting Red Hat developers and CI/CD systems. The affected packages were front-end libraries used in Red Hat product builds.

Key quotes

· 4 pulled
Dozens of packages in the @redhat-cloud-services npm namespace were backdoored with credential-stealing malware aimed at Red Hat developers and CI/CD systems.
Aikido reported 96 compromised versions across 32 packages, downloaded 116,991 times per week.
Red Hat said a compromised GitHub account injected malicious code into packages maintained in a Red Hat GitHub organization.
The malware executed through npm preinstall hooks during npm install, running an obfuscated index.js loader that downloaded and executed a payload to vacuum secrets from npm, GitHub, AWS, and SSH environments.
Snippet from the RSS feed
Dozens of packages in the @redhat-cloud-services npm namespace were backdoored with credential-stealing malware aimed at Red Hat developers and CI/CD systems. Aikido reported 96 compromised versions across 32 packages, downloaded 116,991 times per week. R

You might also wanna read