Skip to main content
Mallory
Back to intelligence
package-repository-poisoningdependency-confusion-typosquatcredential-stealer-activitybuild-pipeline-compromise

Malicious npm Packages Hit Red Hat Scope and Broader Dependency Confusion Campaign

Updated 3d agoFirst seen Jun 1, 202635 sources

More than 31 packages published under the @redhat-cloud-services npm scope were found carrying a multi-stage credential-stealing payload that executed automatically during installation through preinstall hooks. Researchers said the malware targeted GitHub and npm tokens, AWS, GCP, and Azure credentials, Kubernetes and HashiCorp Vault secrets, CircleCI data, and local environment details, with one analyzed package — @redhat-cloud-services/host-inventory-client@5.0.3 — containing a 4.2 MB obfuscated harvester. The malicious releases were reportedly published via GitHub Actions OIDC from the RedHatInsights/javascript-clients repository, pointing to either compromise of the upstream CI/CD pipeline or abuse of its trust configuration; the affected packages collectively had roughly 116,000 weekly downloads.

The incident emerged alongside a separate active npm dependency-confusion campaign identified by Microsoft, in which a single actor used spoofed organizational namespaces, inflated versions such as 100.100.100, and obfuscated postinstall.js code to force installation of malicious packages in corporate developer environments. Microsoft said the payload currently focused on reconnaissance but could be switched remotely to steal credentials, exfiltrate data, or deploy a backdoor, and linked the activity to shared infrastructure and the domain oob.moika.tech. Registry teams removed the malicious packages, while defenders were urged to rotate exposed keys, enable 2FA, audit lockfiles, downgrade to safe package versions, and consider disabling install scripts during npm package installation.

Share:
Malicious npm Packages Hit Red Hat Scope and Broader Dependency Confusion Campaign
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

13 events from the most recent confirmed update back to the earliest known activity.

13 EVENTS
Jun 2, 202613d ago

Researchers report Shai-Hulud campaign remains active with new GitHub-linked tradecraft

On June 2, 2026, OX Security reported that the Shai-Hulud/Miasma npm malware campaign was still active and using a sophisticated six-stage infection chain with GitHub-based exfiltration, command-and-control, and payload delivery. The researchers also assessed the activity may involve a different threat actor than the one behind the Telnyx and LiteLLM compromises and identified another potentially malicious GitHub user continuing the operation.

Six Stages and an Endless Loop: Shai-Hulud Gets Sophisticated

Red Hat discloses 32 affected packages and weekly download volume

Red Hat said the software pipeline compromise affected 32 packages that were downloaded about 117,000 times per week before removal. The company also said that, based on current findings, customers do not need to take action.

Red Hat removes tainted packages after software pipeline compromise | The Record from Recorded Future News
Jun 1, 202614d ago

Wiz says two malicious Red Hat npm package versions remained available

Wiz reported on June 1, 2026 that although most malicious @redhat-cloud-services npm releases had been revoked, two malicious versions were still available at the time of writing. The finding indicated remediation was still incomplete despite broader package takedowns already underway.

Miasma: Supply Chain Attack Targeting RedHat npm Packages | Wiz Blog

Red Hat says affected npm packages were removed and customer environments unaffected

Red Hat stated that the compromised `@redhat-cloud-services` npm packages had been removed and said the affected packages were limited to internal development tooling. The company reported no identified impact to customer, partner, or production environments.

Red Hat npm packages compromised to steal developer credentials

Researchers disclose expanded impact and malware details in Red Hat npm compromise

On 2026-06-01, reporting said more than 30 legitimate npm packages in the @redhat-cloud-services scope were backdoored in a supply-chain attack. The report described the payload as a Mini Shai-Hulud variant that stole a broad range of credentials, used disguised exfiltration and GitHub dead drops, established persistence on Linux and macOS, and could wipe a user’s home directory if stolen GitHub tokens were revoked.

Multiple Red Hat Cloud Services npm Packages Compromised to Deploy Credential-Stealing Malware

StepSecurity and Aikido file disclosures in three RedHatInsights repositories

On 2026-06-01, StepSecurity and Aikido filed disclosure reports in three affected RedHatInsights repositories after detecting malicious @redhat-cloud-services npm releases. The disclosures expanded coordinated response beyond the previously noted issue in RedHatInsights/javascript-clients#492.

Miasma: Red Hat npm Packages Hit by Shai-Hulud Variant

Disclosure issue filed for compromised Red Hat npm packages

A disclosure issue was filed as RedHatInsights/javascript-clients#492, and coordination with maintainers began to confirm the scope of the compromise and remove the malicious releases.

Multiple redhat-cloud-services npm Packages compromised - StepSecurity

Researchers suggest compromised Red Hat GitHub account enabled malicious commits

On June 1, 2026, researchers reported evidence that a compromised Red Hat employee GitHub account may have been the initial access point in the npm supply-chain attack. The account was allegedly used to inject malicious orphan commits into RedHatInsights repositories and bypass code review before the backdoored packages were published.

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

Researchers trace Red Hat package compromise to CI/CD publishing path

Analysis of the compromised @redhat-cloud-services packages found the malicious releases were published via GitHub Actions OIDC from the RedHatInsights/javascript-clients repository, suggesting compromise or abuse of the upstream CI/CD trust path.

Multiple redhat-cloud-services npm Packages compromised - StepSecurity

Malicious packages identified in @redhat-cloud-services scope

On June 1, 2026, researchers identified malicious npm packages in the @redhat-cloud-services scope, including a release that executed a preinstall hook to deploy a multi-stage credential harvester during npm installation.

Multiple redhat-cloud-services npm Packages compromised - StepSecurity
May 30, 202616d ago

Registry security teams remove malicious npm packages

Microsoft reported that registry security teams removed the malicious packages tied to the dependency confusion campaign after identifying the activity and linking the maintainer accounts to one operator.

npm Dependency Confusion Attack: New Malware Discovered
May 29, 202617d ago

Additional malicious npm packages published in same campaign

The same dependency confusion campaign continued on May 29, 2026, with more malicious npm packages published under lookalike organizational namespaces as part of the same operation.

npm Dependency Confusion Attack: New Malware Discovered
May 28, 202618d ago

Threat actor publishes malicious npm packages in dependency confusion campaign

Microsoft Threat Intelligence said a single threat actor published dozens of malicious npm packages through three maintainer accounts on May 28 and May 29, 2026, using spoofed internal package scopes and inflated version numbers to win dependency resolution in targeted corporate environments.

npm Dependency Confusion Attack: New Malware Discovered
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

81 LINKEDOpen in app
Threat actors
1 linked
Affected products
25 linked
NpmAmazon Web ServicesVisual Studio CodeGithubDockerClaude CodeKubernetesAzureHarden RunnerClaudePypiMicrosoft Defender For EndpointCopilotCodexLitellmApparmorVaultJiraGoogle SearchGithub CliSigstoreSentineloneNode.JsPytorch LightningAws-Secrets-Manager
Organizations
43 linked
Red HatGitHubAikido SecurityHashicorpnpm, Inc.Microsoft CorporationGoogleAmazon Web ServicesWizStepSecurityAnthropicCircle Internet GroupSocketSAPBitwardenOx SecurityTanstackSemgrepJfrogInternational Business MachinesMistral AIOpenaiDockerCrowdStrikeSnykCircle Internet FinancialLightning AILitellmTruesecBleepingComputerPalo Alto NetworksChainguardTenableGitLabSonatypeCarbon BlackOrca SecuritySentinelOneSafeDepPhoenix SecurityMercorTelnyxTeamPCP
Breaches
7 linked
REDHAT-2026-06REDHAT-2025-12REDHAT-CLOUD-SERVICES-2026-06REDHAT-2026-05REDHATINC-2026-06MERCOR-2026-06LITELLM-2026-06
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Malicious npm Packages Hit Red Hat Scope and Broader Dependency Confusion Campaign | Mallory