Dozens of Red Hat packages backdoored through its official NPM channel

TL;DR AI
2 min readKey summary
Dozens of Red Hat’s official NPM packages were backdoored in a supply-chain attack tied to the Shai-Hulud worm.
Attackers appear to have abused a compromised GitHub Actions OIDC CI/CD path to publish the malicious packages.
The worm then tried to steal CI/CD and cloud credentials from affected systems.
Red Hat says it removed the malicious packages and has seen no customer, partner, or production impact so far.
Security firms have published indicators of compromise and lists of affected packages to help defenders respond.
