Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
Incidents: Red Hat npm packages compromised in Miasma campaign steal credentials and propagate via worm-like malware.
Deep Analysis and Expert Commentary
The Miasma campaign exemplifies the growing sophistication of supply chain attacks, leveraging compromised developer accounts to inject malicious code into trusted packages. The malware's preinstall hook targets CI/CD pipelines, cloud identities, and local developer environments, suggesting a multi-stage attack strategy. Unique payload encryption per infection complicates detection, while persistence mechanisms like VS Code task automation ensure long-term access. The use of GitHub as a fallback exfiltration channel indicates adaptability. Defenders must prioritize credential rotation, artifact invalidation, and thorough environment audits, as uninstalling packages alone is insufficient due to embedded persistence.
Action Items
- Isolate and remediate hosts with affected npm packages installed.
- Rotate all exposed credentials, including GitHub tokens and cloud keys.
- Audit CI/CD pipelines and developer tools for malicious modifications.
Original Article Brief Intro
The Hacker News · 2026-06-01 · Incidents: Red Hat npm packages compromised in Miasma campaign steal credentials and propagate via worm-like malware.
Related Terms and Notes
Malware Families
- worm
Techniques / TTPs
- credential harvesting
- credential_theft
- Miasma — A supply chain attack campaign targeting Red Hat npm packages with credential-stealing malware.
- Mini Shai-Hulud — A reference to prior attack campaigns using similar tactics, now open-sourced by TeamPCP.
- supply chain attack
Context Notes
- Miasma
- npm
- npm compromise
- Red Hat
- Red_Hat
- supply_chain