Dozens of Red Hat packages backdoored through its offical NPM channel

Dozens of Red Hat packages backdoored through its offical NPM channel

A significant security incident has emerged involving compromised official Red Hat NPM accounts that were exploited to distribute a harmful worm. This worm is capable of infiltrating systems, stealing sensitive credentials, and potentially accessing more confidential data. Reports from the cybersecurity firm Aikido indicate that the supply-chain attack commenced on Monday and continued to pose a threat at the time of reporting. The attack originated from the takeover of the @redhat-cloud-services account, a trusted source for developers utilizing Red Hat cloud services within the npm repository. The method through which the threat actor gained access to this legitimate channel remains unclear, but it likely involved the compromise of necessary credentials, possibly stemming from an earlier supply-chain breach. More than 30 packages appear to have been compromised, executing an obfuscated payload during the npm installation process. This occurs prior to a developer's actual use of the packages in a production environment. A thorough analysis by cybersecurity firm Socket has revealed that the malware is specifically engineered to gather sensitive credentials, including GitHub action secrets, npm tokens, Kubernetes credentials, and various cloud service access keys. Once a device is infected, the worm propagates by republishing the backdoored packages to other third-party accounts that the compromised system can access. Following the incident, most of the affected packages were removed within hours. Researchers at Socket have advised organizations to consider any system that installed one of the affected @redhat-cloud-services package versions as potentially compromised. They emphasized that the malicious payload activates during the npm installation phase, which occurs before the application code uses the package, making exposure reliant on the installation or CI process rather than on runtime usage. Infected systems encrypt stolen credentials and transmit them through web requests. Moreover, the malware has a fallback mechanism that allows it to publish the encrypted data into a compromised GitHub repository if it possesses the necessary credentials.

Sources : Ars Technica

Published On : Jun 01, 2026, 19:50

Mobile
India's Smartphone Market Faces Turbulence Amid Rising Memory Costs

In a significant shift for India's smartphone landscape, rising memory chip prices are reshaping the market dynamics, wi...

TechCrunch | Jul 17, 2026, 20:35
India's Smartphone Market Faces Turbulence Amid Rising Memory Costs
Computing
Amazon Addresses AWS Billing Glitch Affecting Customers

On Friday, numerous users of Amazon's cloud services were taken aback by unexpected billing estimates indicating they ow...

TechCrunch | Jul 17, 2026, 15:50
Amazon Addresses AWS Billing Glitch Affecting Customers
Cybersecurity
Patreon Takes a Stand Against AI Content Scrapers with New Blocking Measures

Patreon, the popular membership platform catering to content creators, is intensifying its efforts to prevent artificial...

TechCrunch | Jul 17, 2026, 15:50
Patreon Takes a Stand Against AI Content Scrapers with New Blocking Measures
AI
Meta Explores AI Infrastructure Leasing Deal with Anthropic

Meta is currently in discussions with the AI startup Anthropic regarding the potential leasing of its extensive computin...

CNN | Jul 17, 2026, 21:15
Meta Explores AI Infrastructure Leasing Deal with Anthropic
Startups
Agility Robotics Expands Operations Near Tesla, Aiming for Humanoid Robot Leadership

Agility Robotics is set to launch a substantial 60,000-square-foot facility in Fremont, California, strategically locate...

TechCrunch | Jul 17, 2026, 20:35
Agility Robotics Expands Operations Near Tesla, Aiming for Humanoid Robot Leadership
View All News