Switch language한국어
Back to the list

Malicious code found in Red Hat’s npm packages

TL;DR AI

Key summary

2 min read
  1. Security researchers found malicious code in multiple npm packages published under Red Hat’s name.

  2. The malware likely came from a supply chain attack tied to a compromised employee GitHub account.

  3. It executed on install via a preinstall hook and was built to steal developer and cloud credentials.

  4. Red Hat removed the packages, launched an investigation, and said it has not found evidence of customer or production impact.

Read the original