Compromised Red Hat npm packages downloaded over 80,000 times in one week – supply chain attack still ongoing



  • Red Hat npm packages compromised with Mini Shai-Hulud variant
  • Attackers target GitHub secrets and cloud credentials
  • Copycat worm shows themed but similar tradecraft

Numerous Red Hat npm packages were recently compromised and tainted with a variant of the Mini Shai-Hulu worm, targeting GitHub Actions secrets, npm tokens, and other valuable information. Thousands of developers and projects are potentially at risk.

Recently, a single Red Hat employee has had their GitHub account compromised. The miscreants used the access to infiltrate, and then compromise, dozens of npm packages.

https://cdn.mos.cms.futurecdn.net/VsnoQAEmxjEvebB3dyY9Pj-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img