Skip to main content
Sign in

Miasma RedHat npm Supply Chain Attack

avoid.net/miasma-redhat-npm-supply-chain-attack2/100·92% conf.
[AI-DRAFTED · AWAITING VERIFICATION]
anchored·5ihgTR…oJDT

Summary

Miasma is a self-propagating credential-stealing worm that compromised 32 official npm packages under the @redhat-cloud-services namespace on June 1, 2026, affecting an estimated 80,000 to 117,000 weekly downloads. The attack was facilitated by a compromised Red Hat employee GitHub account and used GitHub Actions OIDC trusted publishing to inject a 4.2 MB obfuscated preinstall payload derived from the publicly released Mini Shai-Hulud malware framework attributed to the threat actor group TeamPCP. While not a cryptocurrency-specific attack, the worm harvests cloud credentials, CI/CD secrets, and developer tokens — including Anthropic API keys — from any environment running the affected packages, and it is highly relevant to crypto developers who use these packages in their build pipelines.

Have evidence about Miasma RedHat npm Supply Chain Attack?
0
Accepted
1
Under review
0
Rejected / revoked

Community submissions

  • Under reviewincriminatingWayback pending6/16/2026, 11:07:36 AM

    [Scout] undefined

    avoid-scout

Timeline(13 events)

2026-04-13

Red Hat employee GitHub credentials appear in infostealer logs, approximately 7 weeks before weaponization.

Cloud Security Alliance Research Note; Wiz Blog

2026-04-22

Bitwarden CLI compromised via poisoned GitHub Actions workflow in the Mini Shai-Hulud campaign; payload targets crypto wallet data.

Aikido Security; The Hacker News

2026-04-29

Four SAP npm packages compromised via leaked npm token in the Mini Shai-Hulud campaign.

Aikido Security

2026-04-30

PyTorch Lightning package compromised on PyPI as part of the same campaign.

Aikido Security

2026-05-12

TeamPCP open-sources the full Mini Shai-Hulud worm source code on GitHub under MIT License; simultaneously announces a $1,000 BreachForums contest for the largest supply chain attack using the code. Concurrently, the campaign expands to 160+ packages.

ReversingLabs; Tenable; Security Boulevard

2026-05-15

Additional Red Hat employee credentials detected in infostealer logs.

The Hacker News

2026-05-19

Microsoft's DurableTask npm package compromised in the Mini Shai-Hulud campaign.

Aikido Security

2026-05-20

Nine malicious Polymarket-branded npm packages published targeting crypto wallet keys.

SafeDep

2026-05-24

Socket reports TrapDoor campaign: 34+ malicious packages across npm, PyPI, and Crates.io targeting crypto and DeFi developers.

CyberLeveling

2026-05-29

First commit containing the 'Miasma: The Spreading Blight' string appears in RedHatInsights repositories.

The Hacker News

2026-06-01

Miasma attack executes in two waves (10:53 UTC and 13:44–13:46 UTC). Malicious commits pushed to RedHatInsights GitHub organization; 96 backdoored versions of 32 @redhat-cloud-services npm packages published with valid SLSA provenance attestations.

Wiz Blog; Orca Security; The Register

2026-06-01

Wiz Research publicly discloses the Miasma campaign. Red Hat removes affected packages from the npm registry and issues a statement that malicious code did not reach customer production systems.

The Register; BleepingComputer

2026-06-03

Cloud Security Alliance publishes research note on Miasma with extended technical analysis.

Cloud Security Alliance
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.

model: claude-sonnet-4-6

generated: 6/15/2026, 5:42:54 PM

last updated: 6/15/2026, 5:43:05 PM

avoid.net — verified advice for a post-truth world