Open Source · · 4 days

Red Hat npm namespace poisoned via a maintainer's editor

An attacker used a Red Hat employee's GitHub account, compromised by a malicious VS Code extension, to inject the Miasma preinstall dropper into 32 @redhat-cloud-services npm packages. Red Hat published 96 malicious versions before pulling them.

Part of Miasma worm rode a build-config file through npm campaign

Red Hat confirmed in early June 2026 that attackers had published malicious versions of 32 npm packages in its @redhat-cloud-services namespace, using an employee's GitHub account that had been compromised through a booby-trapped Visual Studio Code extension.

The affected packages are frontend JavaScript libraries that build the Hybrid Cloud Console at console.redhat.com, Red Hat's web interface for managing subscriptions and cloud services. They are not headline packages, but between them they accounted for roughly 117,000 weekly npm downloads, most of it into build pipelines rather than onto developer laptops.

In security bulletin RHSB-2026-006, published June 2, Red Hat said the intrusion began on May 29, when the attacker used the stolen GitHub account to inject malicious code into repositories in a Red Hat GitHub organization and to alter configuration files in a way designed to infect other developers who worked on them. Ninety-six versions across the 32 packages reached the npm registry. The malware, which researchers had begun tracking as Miasma, arrived as a preinstall script, which meant it executed during npm install before any application code ran.

Red Hat engineering removed the compromised versions from npm after disclosure and said no Red Hat product or enterprise software had been built or shipped with an affected version, so customers were not asked to take action. The entry point drew as much comment as the payload. A developer's editor extension is not usually modeled as part of a vendor's release pipeline, and in this case it was the shortest path to a namespace trusted by everyone who builds against the console.

Notes

  • Red Hat attributed initial access to a GitHub account compromised by a malicious VS Code extension, not to a stolen npm token. The code was injected at the source repository and carried forward into published packages.
  • Red Hat reported 32 packages and 96 versions, with weekly downloads of 116,991 against Wiz's roughly 80,000. No count of successful installs of a malicious version has been published.
  • The per-package version list comes from StepSecurity plus vulnerabilities-client 2.1.8 from ReversingLabs, and now accounts for all 96 versions. No source reviewed identifies the intervening 2.1.10 as malicious.
  • ReversingLabs reported all 31 first-wave loaders unique and published 30 exact mappings; Microsoft published six later-wave hashes. These are component-file checksums, not npm tarball checksums, and are recorded as indicators.

Appendix · Affected releases

3.6.1 sha256 ca4b89f4…9e3a1c07 download unavailable
3.6.2 sha256 89e8be1f…1726eb2b download unavailable
3.6.4 sha256 0d941640…d27dc76f download unavailable
  • SlowMist published all three checksums for the complete redhat-cloud-services-types-3.6.1.tgz archive. Whole-archive checksums for 3.6.2 and 3.6.4 remain unverified.
6.11.3 sha256 2624c8e1…6cad81dd download unavailable
6.11.4 sha256 7e5cb089…bcbcdeb6 download unavailable
6.11.6 sha256 cb413089…21303e75 download unavailable
  • SlowMist published all three checksums for the complete redhat-cloud-services-frontend-components-config-6.11.3.tgz archive. Whole-archive checksums for 6.11.4 and 6.11.6 remain unverified.
4.7.2 sha256 d6f8a342…bde7ab70 download unavailable
4.7.3 sha256 aada32b7…dd973384 download unavailable
4.7.5 sha256 0d4dbc92…8830a8ef download unavailable
  • SlowMist published all three checksums for the complete redhat-cloud-services-rule-components-4.7.2.tgz archive. Whole-archive checksums for 4.7.3 and 4.7.5 remain unverified.
2.1.8 sha256 a4a48f8b…e8c89aae download unavailable
2.1.9 sha256 b03f7fa1…f2a7fe6b download unavailable
2.1.11 sha256 e7c9a78f…837ed7aa download unavailable
  • Tencent's npm mirror retains the complete dist record for 2.1.9, mapping the SHA-1 and signed SHA-512 above to vulnerabilities-client-2.1.9.tgz. The tarball now 404s; no checksum is inferred for 2.1.8 or 2.1.11.
2.3.1 sha256 88896d47…f4e52fe9 download unavailable
2.3.2 sha256 90f66b61…4cd47371 download unavailable
2.3.4 sha256 a58199d3…804a79e7 download unavailable
  • Socket published SHA-256 88896d478986d453f5da79b311de39d9b4b1bea95c21af1d8ef181b0f4e52fe9 for the complete 2.3.1 tarball. Whole-archive checksums for 2.3.2 and 2.3.4 remain unverified.

Indicators

  • advisoryRHSB-2026-006
  • malware_familyMiasma

References

  1. Multiple redhat-cloud-services npm Packages compromised - StepSecuritystepsecurity.io
  2. Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages - Socketsocket.dev
  3. Red Hat npm Packages Compromised in Supply Chain Attack - Linuxiaclinuxiac.com
  4. IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks - The Hacker Newsthehackernews.com
  5. Miasma: Supply Chain Attack Targeting RedHat npm Packages - Wizwiz.io
  6. Miasma Attack Hits Red Hat npm Packages - Snyksnyk.io
  7. Threat Intelligence | Red Hat Cloud Services npm Package Supply Chain Poisoning - SlowMistslowmist.medium.com
  8. Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign - Microsoft Security Blogmicrosoft.com
  9. Dozens of Red Hat npm packages targeted in supply chain attack - Cybersecurity Divecybersecuritydive.com
  10. 31 Red Hat npm packages backdoored by Miasma in 72 seconds - ReversingLabsreversinglabs.com
  11. Tencent npm mirror metadata retaining vulnerabilities-client 2.1.9 dist integritymirrors.cloud.tencent.com

Source record: oss/attacks/redhat-cloud-services/meta.yaml