Miasma Attack Compromises Red Hat npm Packages With Credential Worm

TL;DR. A supply chain attack named Miasma infected Red Hat npm packages, deploying a credential-stealing worm to target developers and infrastructure. - The attackers used obfuscated JavaScript in malicious packages to blend with legitimate code, evading detection. - This incident highlights increasing threats to software supply chains, directly impacting developer tools. - Red Hat has addressed the immediate compromise and advises developers to update packages and review application security.

Sources

Back to QLANKR News