Malicious code found in Red Hat’s npm packages

TL;DR AI
2 min readKey summary
Security researchers found malicious code in multiple npm packages published under Red Hat’s name.
The malware likely came from a supply chain attack tied to a compromised employee GitHub account.
It executed on install via a preinstall hook and was built to steal developer and cloud credentials.
Red Hat removed the packages, launched an investigation, and said it has not found evidence of customer or production impact.



