Skip to main content
AVOID.NET

Miasma npm Supply Chain Attack (Red Hat)

avoid.net/miasma-npm-supply-chain-attack-red-hat0/100·92% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·mZ7AS5…zquK

Summary

On June 1, 2026, a supply chain attack designated 'Miasma' compromised at least 32 npm package releases under the @redhat-cloud-services namespace, collectively receiving approximately 80,000–116,991 weekly downloads. A single Red Hat employee's GitHub account was exploited after credentials appeared in infostealer logs as early as April 13, 2026 — a gap of roughly seven weeks before weaponization. The payload, derived from the TeamPCP 'Mini Shai-Hulud' malware family, is a self-propagating worm that harvests developer and cloud credentials, injects persistent GitHub Actions workflows, and targets 166 cryptocurrency browser extensions.

Connected Entities

5 entities · 60 linked investigations
Organizations
Tokens
Relationships
  • Phantom Walletmentioned withCoinbase(60%)
  • Miasma npm Supply Chain Attack (Red Hat)mentioned withCoinbase(75%)
  • Miasma npm Supply Chain Attack (Red Hat)mentioned withBinance(75%)
  • Miasma npm Supply Chain Attack (Red Hat)mentioned withPhantom Wallet(65%)
  • Miasma npm Supply Chain Attack (Red Hat)mentioned withShai-Hulud / TeamPCP Supply Chain Attack(70%)
Have evidence about Miasma npm Supply Chain Attack (Red Hat)?

Timeline(13 events)

September 2025

Original Shai-Hulud worm emerged as the first self-replicating malware targeting the npm ecosystem, attributed to TeamPCP.

Tenable Mini Shai-Hulud FAQ

13 April 2026

A Red Hat employee's GitHub credential and active session cookie first appeared in infostealer logs, as later identified by Whiteintel.

Whiteintel — Red Hat Miasma Attack: A Linked GitHub Credential Surfaced in Stealer Logs

22 April 2026

Bitwarden CLI compromised via a poisoned GitHub Actions workflow — an early incident in the broader Shai-Hulud campaign wave.

aikido.dev — Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm

12 May 2026

TeamPCP published the full Mini Shai-Hulud source code on GitHub ('Shai-Hulud: Open Sourcing The Carnage') and announced a BreachForums contest incentivizing independent supply chain attacks using the code.

SecurityWeek — TeamPCP Ups the Game, Releases Shai-Hulud Worm's Source Code

15 May 2026

The same Red Hat employee GitHub credential appeared a second time in infostealer logs from a distinct source channel.

Whiteintel — Red Hat Miasma Attack: A Linked GitHub Credential Surfaced in Stealer Logs

29 May 2026

Earliest malicious commit containing the string 'Miasma: The Spreading Blight' detected in the affected RedHatInsights repositories.

The Hacker News — Miasma Supply Chain Attack Compromises Red Hat npm Packages

June 2026

First wave of malicious @redhat-cloud-services packages published between approximately 10:53–10:53 UTC across three repositories.

Wiz — Miasma: Supply Chain Attack Targeting RedHat npm Packages

June 2026

Public disclosure by Wiz Research at approximately 13:00 UTC; most malicious versions revoked from npm.

Snyk — Miasma Supply Chain Attack: Malicious Code in Red Hat Cloud Services npm Packages

June 2026

Second malicious wave published between approximately 13:44–13:46 UTC; root cause identified.

Snyk — Miasma Supply Chain Attack: Malicious Code in Red Hat Cloud Services npm Packages

June 2026

Red Hat published Security Bulletin RHSB-2026-006; stated no customer action required and no Red Hat products were shipped with compromised versions.

Red Hat Security Bulletin RHSB-2026-006

June 2026

The Register reported Socket had identified 95 affected package versions as of 11:00 UTC; combined weekly download count cited as approximately 80,000.

The Register — Shai-Hulud malware worms Red Hat npm packages

2 June 2026

Additional compromised package versions discovered; Microsoft Defender Security Research Team published incident analysis.

Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign — Microsoft Security Blog

3 June 2026

Red Hat Security Bulletin RHSB-2026-006 updated with preliminary findings; investigation described as ongoing.

Red Hat Security Bulletin RHSB-2026-006
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 19 of 20 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 6/24/2026, 12:16:06 PM

last updated: 7/27/2026, 10:56:28 AM

3 views

avoid.net — verified advice for a post-truth world