YOU ARE VIEWING ONE ITEM FROM THE AICRIER FEED

Miasma Worm Compromises Red Hat npm Packages

AICrier tracks AI developer news across Product Hunt, GitHub, Hacker News, YouTube, X, arXiv, and more. This page keeps the article you opened front and center while giving you a path into the live feed.

// WHAT AICRIER DOES

7+

TRACKED FEEDS

24/7

SCRAPED FEED

Short summaries, external links, screenshots, relevance scoring, tags, and featured picks for AI builders.

Miasma Worm Compromises Red Hat npm Packages
OPEN LINK ↗
// 2h agoSECURITY INCIDENT

Miasma Worm Compromises Red Hat npm Packages

More than 30 official npm packages under Red Hat's @redhat-cloud-services scope have been compromised in a supply chain attack that bypassed SLSA provenance checks using GitHub Actions OIDC tokens. The malicious packages execute the 'Miasma' credential-stealing worm via obfuscated preinstall scripts to harvest cloud environment credentials, developer environment tokens, and CI/CD secrets.

// ANALYSIS

This compromise represents a major escalation in supply chain attacks by successfully abusing GitHub Actions OIDC tokens to bypass trust frameworks, obtaining legitimate SLSA provenance attestations for malicious packages. It demonstrates that cryptographically signed artifact verification is only as secure as the identity and access management controls guarding the deployment workflows.

* Attackers exploited a compromised developer GitHub account to inject malicious preinstall hooks into package releases.

* The malware bypassed traditional signature-based detection through valid SLSA provenance attestations and heavy obfuscation.

* Targeted exfiltration specifically focused on developer infrastructure keys (Kubernetes secrets, HashiCorp Vault tokens, NPM/GitHub API keys) and cloud platform identities (Azure, GCP).

* Organizations utilizing @redhat-cloud-services packages must assume complete compromise of credentials present in those environments, requiring immediate system-wide rotation and script execution policies like `--ignore-scripts`.

// TAGS
npmred-hatsecuritysupply-chainmalwaremiasmacredential-theftgithub-actions

DISCOVERED

2h ago

2026-06-01

PUBLISHED

4h ago

2026-06-01

RELEVANCE

9/ 10

AUTHOR

kurmiashish