Compromised Red Hat npm packages downloaded over 80,000 times in one week – supply chain attack still ongoing

https://cdn.mos.cms.futurecdn.net/VsnoQAEmxjEvebB3dyY9Pj-2560-80.jpg
  • Red Hat npm packages compromised with Mini Shai-Hulud variant
  • Attackers target GitHub secrets and cloud credentials
  • Copycat worm shows themed but similar tradecraft

Numerous Red Hat npm packages were recently compromised and tainted with a variant of the Mini Shai-Hulu worm, targeting GitHub Actions secrets, npm tokens, and other valuable information. Thousands of developers and projects are potentially at risk.

Recently, a single Red Hat employee has had their GitHub account compromised. The miscreants used the access to infiltrate, and then compromise, dozens of npm packages.

Wiz, for example, identified 32 packages so far, which receive around 80,000 downloads a week. Socket, on the other hand, claims to have identified 95 packages. Both outfits confirmed that the attack is currently ongoing, and hinted that the number of infected packages will probably grow even bigger.

TeamPCP copycats

All of the packages were published under the Red Hat Cloud Services namespace. The...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more