Multiple official @redhat-cloud-services npm packages were compromised on June 1, 2026 with a credential-stealing worm called 'Miasma', derived from the open-sourced Mini Shai-Hulud malware by threat actor group TeamPCP. Over 30 packages are affected. The malware uses a preinstall script to execute a 4.2 MB obfuscated payload that sweeps for AWS, GCP, Azure credentials, GitHub Actions secrets, Kubernetes tokens, SSH keys, npm/PyPI tokens, Docker credentials, and .env files. Anyone who installed affected package versions should immediately rotate all CI secrets, cloud credentials, SSH keys, and npm tokens. A full list of compromised package versions is provided as indicators of compromise.

4m read timeFrom aikido.dev
Post cover image
Table of contents
Miasma: Is Shai-Hulud back?The preinstall scriptWhat it stealsHow Aikido detects this‍Indicators of Compromise
198 Impressions