Switch language한국어
Back to the list

Backdoors found in dozens of packages distributed through Red Hat's official npm channel

TL;DR AI

Key summary

2 min read
  1. Multiple packages under Red Hat’s official npm channel were compromised and trojanized with install-time malware.

  2. Aikido says 32 packages across 96 versions were affected, and the worm-like malware Miasma stole and exfiltrated GitHub, cloud, and npm credentials via a public GitHub Actions OIDC flow.

  3. Red Hat removed the affected packages and said there is no evidence of impact to customer-facing releases or production environments.

  4. The incident highlights the supply-chain risk of abusing trusted distribution paths to harvest secrets from developers and CI/CD systems.

Read the original