On June 1, 2026, multiple npm packages in the @redhat-cloud-services scope were published with malicious versions containing a 4.1 MB obfuscated JavaScript preinstall hook. The hook runs a multi-stage loader: a Caesar-shifted wrapper decodes to AES-128-GCM encrypted payloads, which download the Bun runtime and execute a 620 KB credential stealer targeting AWS, Azure, GCP, HashiCorp Vault, Kubernetes, GitHub Actions OIDC, npm, Bitwarden, and 1Password. Exfiltration uses the GitHub GraphQL API via stolen tokens, and the worm can self-propagate by republishing malicious npm package versions using npm Trusted Publishing OIDC. Detailed IOCs, detection commands, and a 7-step remediation checklist are provided, including rotating all credentials on affected machines and hunting for suspicious branches named 'chore/add-codeql-static-analysis'.