Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Pac...
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Socket's threat research team has uncovered a malicious npm supply chain campaign targeting @redhat-cloud-services packages. The attack uses preinstall hooks to execute obfuscated payloads automatically during npm install, before any code is imported. The malware collects GitHub Actions secrets, npm tokens, cloud credentials (AWS, Azure, GCP), Kubernetes and Vault material, SSH keys, and more. It uses AES-GCM encrypted exfiltration with a GitHub API fallback channel, daemonizes itself on developer workstations, and can propagate further by modifying GitHub repositories and workflows using stolen tokens. The campaign shares tactics with the Shai-Hulud open-source attack tooling. Remediation guidance includes isolating affected systems, rotating all exposed credentials, auditing GitHub and npm activity, and strengthening CI/CD dependency controls.