Dozens of Red Hat packages backdoored through its offical NPM channel
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Official Red Hat NPM accounts (@redhat-cloud-services) were compromised in an active supply-chain attack that pushed a malicious worm to over 30 packages. The malware executes during npm install — before any code imports the package — collecting sensitive credentials including GitHub Actions secrets, npm tokens, Kubernetes and Vault material, and cloud service credentials. It then spreads by republishing backdoored packages to third-party accounts the infected machine has access to, and exfiltrates encrypted credentials via web requests or a compromised GitHub repository as a fallback. Organizations that installed affected package versions should treat those systems as compromised immediately.