Red Hat npm Miasma credential-stealing campaign

An npm supply chain attack has been identified affecting 32 maliciously modified packages across more than 90 versions under the @redhat-cloud-services npm scope. The compromise followed an attacker gaining access to the personal GitHub account of a Red Hat employee and using it to push hidden code changes into RedHatInsights repositories without code review. Because the changes originated from a legitimate Red Hat setup, they shipped with valid SLSA provenance attestations and appeared authentic. The malware, named Miasma, is a worm and credential stealer based on Mini Shai-Hulud, an open-source malware framework. On installation it searches for credentials for Google Cloud, Microsoft Azure and Amazon Web Services, SSH keys, password data and AI tool keys. It spreads further by querying the npm registry for other packages the host is permitted to modify and publishing the same malicious payload to them.

What this means for your organisation

Signatures and attestations prove where code came from, not that the code is safe. When a developer's personal account is the entry point, the attacker inherits the trust the entire supply chain rests on. For an organisation the consequence is that cloud credentials may have been extracted from a build server without anyone logging in anywhere. This is also the core of the NIS2 supply chain security requirements.

Berigo recommends

  • Check whether affected packages and versions appear in your builds and lock files, and rotate every credential that may have been exposed on the build environment.
  • Require code review and protected branches for all repositories that publish packages, with no exception for hotfixes.
  • Run install scripts in isolated build environments without standing cloud access, and use short-lived credentials.
  • Maintain software bills of materials so the question "do we use this package?" can be answered the same day.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch