Miasma Attack Compromises Red Hat npm Packages With Credential Worm
TL;DR. A supply chain attack named Miasma infected Red Hat npm packages, deploying a credential-stealing worm to target developers and infrastructure. - The attackers used obfuscated JavaScript in malicious packages to blend with legitimate code, evading detection. - This incident highlights increasing threats to software supply chains, directly impacting developer tools. - Red Hat has addressed the immediate compromise and advises developers to update packages and review application security.
- A supply chain attack, Miasma, affected Red Hat npm packages.
- The attack deployed a credential-stealing worm targeting developer credentials.
- Malicious JavaScript was obfuscated within legitimate-looking packages to avoid detection.
- The incident underscores critical vulnerabilities in modern software supply chains.
- Red Hat has mitigated the issue and recommends urgent security measures.
Sources
- Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm — thehackernews.com
- arstechnica.com — arstechnica.com
- theregister.com — theregister.com
- securityweek.com — securityweek.com