Backdoors found in dozens of packages distributed through Red Hat's official npm channel

TL;DR AI
2 min readKey summary
Multiple packages under Red Hat’s official npm channel were compromised and trojanized with install-time malware.
Aikido says 32 packages across 96 versions were affected, and the worm-like malware Miasma stole and exfiltrated GitHub, cloud, and npm credentials via a public GitHub Actions OIDC flow.
Red Hat removed the affected packages and said there is no evidence of impact to customer-facing releases or production environments.
The incident highlights the supply-chain risk of abusing trusted distribution paths to harvest secrets from developers and CI/CD systems.



