Security researchers have uncovered a sophisticated software supply chain attack campaign dubbed Miasma, which compromised multiple npm packages published under Red Hat's @redhat-cloud-services namespace. The campaign delivers a credential-stealing worm designed to harvest developer secrets, cloud credentials, and CI/CD tokens while enabling potential downstream propagation across software development environments. Researchers describe the operation as a new variant of the previously observed Mini Shai-Hulud malware campaign, sharing similar tactics focused on install-time execution, credential theft, and software supply chain compromise. The attack originated after a Red Hat employee's GitHub account was reportedly compromised, allowing attackers to push unauthorized commits and publish malicious package versions through trusted infrastructure. Researchers identified at least 32 affected npm packages containing obfuscated preinstall scripts that automatically execute during package installation. The malware collects GitHub Actions secrets, npm tokens, cloud credentials, Kubernetes and HashiCorp Vault secrets, SSH keys, Git credentials, and other sensitive developer artifacts. Unlike traditional malware that requires execution after installation, Miasma activates immediately during the package installation process, significantly increasing the likelihood of compromise. The worm uses encrypted exfiltration mechanisms and GitHub-based fallback channels to transmit stolen data to attacker-controlled infrastructure. Researchers also observed attempts to tamper with GitHub workflows, escalate privileges within CI/CD environments, establish persistence through Visual Studio Code and Anthropic Claude Code integrations, and harvest Azure and Google Cloud identities. The malware generates unique encrypted payloads for each infection, complicating detection and forensic analysis. Organizations that installed affected package versions are advised to immediately isolate impacted systems, rotate exposed credentials, audit CI/CD pipelines, and inspect developer environments for persistence artifacts.
A recently disclosed supply chain vulnerability in Anthropic’s Claude Code GitHub Actions integration exposed numerous repositories to potential compromise through a single malic...
A critical security vulnerability affecting KMW CCTV cameras has been disclosed under CVE-2026-5386. The flaw allows attackers to bypass authentication controls and change device c...
A critical vulnerability, tracked as CVE-2026-4387, has been disclosed in StrongDM, exposing organizations to authentication token theft and session hijacking. Discovered by Specte...