More than 31 packages published under the @redhat-cloud-services npm scope were found carrying a multi-stage credential-stealing payload that executed automatically during installation through preinstall hooks. Researchers said the malware targeted GitHub and npm tokens, AWS, GCP, and Azure credentials, Kubernetes and HashiCorp Vault secrets, CircleCI data, and local environment details, with one analyzed package — @redhat-cloud-services/host-inventory-client@5.0.3 — containing a 4.2 MB obfuscated harvester. The malicious releases were reportedly published via GitHub Actions OIDC from the RedHatInsights/javascript-clients repository, pointing to either compromise of the upstream CI/CD pipeline or abuse of its trust configuration; the affected packages collectively had roughly 116,000 weekly downloads.
The incident emerged alongside a separate active npm dependency-confusion campaign identified by Microsoft, in which a single actor used spoofed organizational namespaces, inflated versions such as 100.100.100, and obfuscated postinstall.js code to force installation of malicious packages in corporate developer environments. Microsoft said the payload currently focused on reconnaissance but could be switched remotely to steal credentials, exfiltrate data, or deploy a backdoor, and linked the activity to shared infrastructure and the domain oob.moika.tech. Registry teams removed the malicious packages, while defenders were urged to rotate exposed keys, enable 2FA, audit lockfiles, downgrade to safe package versions, and consider disabling install scripts during npm package installation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
On June 2, 2026, OX Security reported that the Shai-Hulud/Miasma npm malware campaign was still active and using a sophisticated six-stage infection chain with GitHub-based exfiltration, command-and-control, and payload delivery. The researchers also assessed the activity may involve a different threat actor than the one behind the Telnyx and LiteLLM compromises and identified another potentially malicious GitHub user continuing the operation.
Red Hat said the software pipeline compromise affected 32 packages that were downloaded about 117,000 times per week before removal. The company also said that, based on current findings, customers do not need to take action.
Wiz reported on June 1, 2026 that although most malicious @redhat-cloud-services npm releases had been revoked, two malicious versions were still available at the time of writing. The finding indicated remediation was still incomplete despite broader package takedowns already underway.
Red Hat stated that the compromised `@redhat-cloud-services` npm packages had been removed and said the affected packages were limited to internal development tooling. The company reported no identified impact to customer, partner, or production environments.
On 2026-06-01, reporting said more than 30 legitimate npm packages in the @redhat-cloud-services scope were backdoored in a supply-chain attack. The report described the payload as a Mini Shai-Hulud variant that stole a broad range of credentials, used disguised exfiltration and GitHub dead drops, established persistence on Linux and macOS, and could wipe a user’s home directory if stolen GitHub tokens were revoked.
On 2026-06-01, StepSecurity and Aikido filed disclosure reports in three affected RedHatInsights repositories after detecting malicious @redhat-cloud-services npm releases. The disclosures expanded coordinated response beyond the previously noted issue in RedHatInsights/javascript-clients#492.
A disclosure issue was filed as RedHatInsights/javascript-clients#492, and coordination with maintainers began to confirm the scope of the compromise and remove the malicious releases.
On June 1, 2026, researchers reported evidence that a compromised Red Hat employee GitHub account may have been the initial access point in the npm supply-chain attack. The account was allegedly used to inject malicious orphan commits into RedHatInsights repositories and bypass code review before the backdoored packages were published.
Analysis of the compromised @redhat-cloud-services packages found the malicious releases were published via GitHub Actions OIDC from the RedHatInsights/javascript-clients repository, suggesting compromise or abuse of the upstream CI/CD trust path.
On June 1, 2026, researchers identified malicious npm packages in the @redhat-cloud-services scope, including a release that executed a preinstall hook to deploy a multi-stage credential harvester during npm installation.
Microsoft reported that registry security teams removed the malicious packages tied to the dependency confusion campaign after identifying the activity and linking the maintainer accounts to one operator.
The same dependency confusion campaign continued on May 29, 2026, with more malicious npm packages published under lookalike organizational namespaces as part of the same operation.
Microsoft Threat Intelligence said a single threat actor published dozens of malicious npm packages through three maintainer accounts on May 28 and May 29, 2026, using spoofed internal package scopes and inflated version numbers to win dependency resolution in targeted corporate environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
35 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcehackread.com
Open sourcezdnet.fr
Open sourcemalware.news
Open sourcesemgrep.dev
Open sourcesecurityonline.info
Open sourceopennet.me
Open sourceopennet.ru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.