Miasma Malware Hits 32 Red Hat Packages via Compromised GitHub Account
On 1 June 2026, experts from multiple cybersecurity firms found a major supply chain compromise affecting software components used by Red Hat. Security firms Microsoft, Wiz Research, Snyk, and Aikido reported that hackers sneaked harmful code into software packages under the @redhat-cloud-services name on npm, which is a public library where developers get building blocks for their code.
The issue impacted at least 32 packages, leading to 96 compromised versions, which help run the Red Hat Hybrid Cloud Console and are downloaded around 80,000 to 117,000 times every week. Given the modules’ wide integration, the impact radius extends beyond Red Hat’s infrastructure to external development pipelines.
How the Infrastructure Was Exploited
The hackers didn’t guess passwords or use typosquatted webpages. Instead, they got into the personal GitHub account of a real Red Hat worker. They used this account to push hidden code changes (malicious orphan commits) directly into...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE