Miasma npm worm hijacks Red Hat

- On June 1, Microsoft and Red Hat disclosed that the Miasma npm worm had compromised dozens of @redhat-cloud-services packages and infected installs. (microsoft.com) - Microsoft said 32 maliciously modified packages across more than 90 versions harvested credentials from GitHub, AWS, Azure, GCP, Vault and Kubernetes. (microsoft.com) - Red Hat said compromised versions were removed from npm, and customers can track updates in advisory RHSB-2026-006. (access.redhat.com)

Microsoft’s Defender Security Research Team said on June 2 that a supply-chain attack dubbed Miasma compromised more than 90 versions of packages in Red Hat’s `@redhat-cloud-services` npm scope and turned package installation into a credential-theft event. Red Hat said in advisory RHSB-2026-006 that 32 npm packages were published in compromised form and later removed from the npm registry. (microsoft.com) Microsoft said the malware harvested secrets from developer machines and CI/CD environments, then attempted to spread by compromising additional maintainer packages and republishing poisoned releases with forged provenance. The campaign matters because the malicious code ran during installs, before many downstream users would have reason to suspect a problem. (access.redhat.com) Microsoft said the payload used layers of obfuscation and encryption, downloaded the Bun JavaScript runtime, and launched a second-stage stealer aimed at cloud, source-code and local developer credentials. Quantstamp said in its June security roundup that the attack stemmed from a compromised Red Hat employee GitHub account that pushed malicious orphan commits to two Red Hat Insights repositories. ### How did the worm get into Red Hat’s npm packages? Quantstamp said a compromised Red Hat employee GitHub account pushed malicious orphan commits into two `RedHatInsights` repositories, bypassing code review in two waves. (microsoft.com) Red Hat said its investigation identified 32 affected packages under the `@redhat-cloud-services` namespace and found no evidence that Red Hat products or enterprise software were built or shipped with those compromised versions. Microsoft said the malware used preinstall execution to run as packages were installed. That gave the attackers code execution on developer workstations and CI/CD runners before the package’s normal functionality came into play. (microsoft.com) ### What exactly did the malware try to steal? Microsoft said the secondary payload targeted credentials from GitHub, npm, Amazon Web Services, Microsoft Azure, Google Cloud Platform, HashiCorp Vault and Kubernetes. On developer systems, the company said, the malware also stole SSH keys, browser data, wallet data and command-line credentials. (quantstamp.com) In CI/CD environments, Microsoft said the malware scraped GitHub Actions runner memory for secrets and used passwordless `sudo` in some cases to escalate privileges. Snyk said the malicious preinstall hook also probed cloud identities and could republish other packages, extending the campaign beyond the initial victims. (microsoft.com) ### Why are researchers focused on the provenance angle? Microsoft said the worm could republish poisoned packages with forged Supply-chain Levels for Software Artifacts, or SLSA, provenance as part of its downstream propagation. That meant the attackers were not only inserting malicious code into trusted packages, but also attaching release metadata that could make those releases appear legitimate inside automated build and verification pipelines. (microsoft.com) Socket said Miasma was first observed in compromised Red Hat Cloud Services packages before spreading to additional victims in other npm ecosystems. Quantstamp described the payload as derived from the Mini Shai-Hulud malware that TeamPCP had open-sourced earlier, with naming changes but similar tradecraft. (microsoft.com) ### Was Red Hat’s own product line affected? Red Hat said no Red Hat products or enterprise software were identified as built or shipped with a compromised version of the affected npm packages. The company said build-system and dependency-tracking analysis confirmed that no product builds contained compromised package versions. The company’s advisory still treated the npm compromise as a customer incident. (microsoft.com) Red Hat said engineering removed the compromised versions from npm following disclosure and published package-level guidance in RHSB-2026-006. ### What should users watch next? Red Hat’s next public reference point is advisory RHSB-2026-006, which lists the affected `@redhat-cloud-services` packages and remediation guidance. (socket.dev) Microsoft’s June 2 research post remains the most detailed public account of the attack chain, stolen credential targets and propagation methods disclosed so far. (microsoft.com) (access.redhat.com)

Get your own daily briefing

Scout delivers personalized news, insights, and conversations tailored to your role and industry.

Download on the App Store

Shared from Scout - Be the smartest in the room.