Switch language한국어
Back to the list

Dozens of Red Hat packages backdoored through its official NPM channel

TL;DR AI

Key summary

2 min read
  1. Dozens of Red Hat’s official NPM packages were backdoored in a supply-chain attack tied to the Shai-Hulud worm.

  2. Attackers appear to have abused a compromised GitHub Actions OIDC CI/CD path to publish the malicious packages.

  3. The worm then tried to steal CI/CD and cloud credentials from affected systems.

  4. Red Hat says it removed the malicious packages and has seen no customer, partner, or production impact so far.

  5. Security firms have published indicators of compromise and lists of affected packages to help defenders respond.

Read the original