Relevance: primary · Type: event
Confidence95%
Official Red Hat NPM accounts have been compromised and used to push a malicious worm that spreads from machine to machine, where it pilfers sensitive credentials.
Relevance: primary · Type: event
Confidence95%
The supply-chain attack began Monday and remained active at the time the initial report was published.
Relevance: primary · Type: event
Confidence95%
The attack resulted from a threat actor taking control of @redhat-cloud-services, a legitimate channel in the npm repository reserved for official Red Hat packages.
Relevance: primary · Type: event
Confidence95%
More than 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were compromised.
Relevance: supporting · Type: event
Confidence90%
Aikido reported that 32 packages and 96 package versions were affected by the compromise.
Relevance: primary · Type: event
Confidence95%
The compromised packages execute an obfuscated payload during the npm install process, before the package is imported or used in production.
Relevance: primary · Type: event
Confidence90%
Security firm Socket analyzed the malware and found it is designed to collect sensitive credentials, including GitHub action secrets, npm tokens, Kubernetes and Vault material, and credentials for other cloud services.
Relevance: primary · Type: event
Confidence90%
The worm spreads by republishing backdoored packages to third-party accounts the infected device has access to.
Relevance: supporting · Type: event
Confidence90%
Most, but not all, of the malicious packages had been taken down in the hours following the incident.
Socket researchers
Relevance: primary · Type: quote
Confidence95%
"Organizations should treat any system that installed one of the affected @redhat-cloud-services package versions as potentially compromised," Socket researchers wrote.
Socket researchers
Relevance: primary · Type: quote
Confidence95%
"The payload executes during npm install, before application code imports or uses the package, so exposure depends on installation or CI execution, not runtime use."
Relevance: primary · Type: event
Confidence90%
Once a system is infected, it encrypts the credentials and sends them through a web request.
Relevance: supporting · Type: event
Confidence90%
A fallback mechanism allows the malware to publish the encrypted data into a compromised GitHub repository if it has the credentials for it.
Relevance: supporting · Type: background
Confidence90%
The worm is dubbed Shai-Hulud and shares characteristics with malware released last month as open source.
Relevance: supporting · Type: background
Confidence90%
TeamPCP was the first group to use Shai-Hulud and promoted a competition offering $1,000 to the hacker who carried out the biggest supply-chain attack using the malware.
Relevance: supporting · Type: background
Confidence85%
TeamPCP has also been behind a rash of previous supply-chain attacks.
Relevance: primary · Type: event
Confidence90%
The malware used in the Red Hat compromise is a new variant called 'Miasma.'
Relevance: supporting · Type: event
Confidence90%
Miasma uses the string 'Miasma: The Spreading Blight' as comments in compromised GitHub repositories.
Relevance: supporting · Type: event
Confidence90%
The compromised packages receive roughly 117,000 weekly downloads, according to Aikido.
Relevance: primary · Type: action
Confidence95%
Red Hat said it removed the affected packages after becoming aware of the incident and that the compromise was limited to internal development tooling.
Red Hat spokesperson
Relevance: primary · Type: quote
Confidence95%
"Red Hat is aware of security reports regarding certain npm packages within our development tooling ecosystem. We immediately initiated an investigation and removed the packages from the npm registry," Red Hat told BleepingComputer.
Red Hat spokesperson
Relevance: primary · Type: quote
Confidence95%
"The packages are strictly limited to internal development, and the malicious code was never published for customer consumption via the console.redhat.com system," the email said.
Red Hat spokesperson
Relevance: primary · Type: quote
Confidence95%
"While our investigation is ongoing, we have not identified any impact to customer or partner environments or Red Hat production systems."
Relevance: primary · Type: event
Confidence90%
According to Aikido, the attackers compromised a Red Hat employee's GitHub account and used it to push malicious commits directly to multiple repositories.
Relevance: primary · Type: event
Confidence90%
The malicious commits added a GitHub Actions workflow and a script that abused npm's publishing mechanism to release backdoored packages.
Relevance: supporting · Type: event
Confidence90%
The script uses the id-token: write permission to request a short-lived OIDC token from GitHub, then uses that token to authenticate directly with npm's trusted publishing endpoint and publish backdoored versions of every package in the list.
Relevance: primary · Type: event
Confidence90%
The compromised packages contained a malicious 'preinstall' script that automatically executed a heavily obfuscated malicious index.js file when developers installed the packages.
Relevance: primary · Type: event
Confidence90%
The 'index.js' payload was approximately 4.2 MB in size and is used to steal GitHub Actions secrets, AWS credentials, Google Cloud credentials, Azure service principal credentials, HashiCorp Vault tokens, Kubernetes service account tokens, npm and PyPI publishing tokens, SSH keys, Docker credentials, GPG keys, and `.env` files.
Relevance: supporting · Type: action
Confidence90%
Organizations that installed any affected versions are advised to rotate all credentials, secrets, and tokens utilized by code on the infected device immediately.
Relevance: supporting · Type: event
Confidence90%
OX Security says the malware retains the same credential-stealing functionality as Mini Shai-Hulud but adds additional obfuscation layers, multi-stage payload delivery mechanisms, and enhanced data theft and credential-harvesting features.
Relevance: supporting · Type: event
Confidence90%
At the time of reporting, 309 GitHub repositories have been compromised by the Miasma malware campaign.
Relevance: supporting · Type: background
Confidence80%
It is unclear how the threat actor took control of the namespace, but it almost certainly involved the compromise of credentials required to access it, possibly through a previous supply-chain attack.
forum Comments (0)
No comments yet. Be the first to comment.