Multiple npm packages in the @redhat-cloud-services scope have been found to contain malware injected via a compromised GitHub Actions CI/CD pipeline in the RedHatInsights/javascript-clients repository. The payload is a multi-stage credential harvester targeting GitHub Actions secrets, AWS, GCP, Azure, Kubernetes, HashiCorp Vault, npm, and CircleCI tokens. The malware is also a self-propagating worm that uses stolen npm tokens and npm's bypass_2fa parameter to republish backdoored versions of other packages, bypassing two-factor authentication. The infected index.js file is 4.2 MB (far larger than expected) and uses three layers of obfuscation. StepSecurity and SafeDep have published analyses; Red Hat has not yet issued an advisory.
266 Impressions