tech

Dozens of Red Hat packages backdoored through its official NPM channel

Anyone who has downloaded affected Red Hat packages should investigate immediately.

Dozens of Red Hat packages backdoored through its official NPM channel

TL;DR

  • Official Red Hat NPM accounts (@redhat-cloud-services) were compromised, pushing a malicious worm.
  • The worm, named Shai-Hulud, steals sensitive credentials like GitHub secrets, npm tokens, and Kubernetes material.
  • It spreads by republishing backdoored packages and targets CI/CD systems.
  • The attack involved compromising Red Hat's GitHub Actions OIDC, likely through a prior supply-chain attack.
  • Red Hat stated the malicious code was limited to internal development and did not impact customer environments.
  • Security firms Aikido and Socket identified affected packages and provided indicators of compromise.