Skip to main content
AVOID.NET

Miasma RedHat npm Supply Chain Attack

avoid.net/miasma-redhat-npm-supply-chain-attack2/100·92% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·5ihgTR…oJDT

Summary

Miasma is a self-propagating credential-stealing worm that compromised 32 official npm packages under the @redhat-cloud-services namespace on June 1, 2026, affecting an estimated 80,000 to 117,000 weekly downloads. The attack was facilitated by a compromised Red Hat employee GitHub account and used GitHub Actions OIDC trusted publishing to inject a 4.2 MB obfuscated preinstall payload derived from the publicly released Mini Shai-Hulud malware framework attributed to the threat actor group TeamPCP. While not a cryptocurrency-specific attack, the worm harvests cloud credentials, CI/CD secrets, and developer tokens — including Anthropic API keys — from any environment running the affected packages, and it is highly relevant to crypto developers who use these packages in their build pipelines.

Have evidence about Miasma RedHat npm Supply Chain Attack?
0
Accepted
1
Under review
0
Rejected / revoked

Community submissions

  • Under reviewincriminatingWayback pending6/16/2026, 11:07:36 AM

    [Scout] undefined

    avoid-scout

Timeline(13 events)

13 April 2026

Red Hat employee GitHub credentials appear in infostealer logs, approximately 7 weeks before weaponization.

Cloud Security Alliance Research Note; Wiz Blog

22 April 2026

Bitwarden CLI compromised via poisoned GitHub Actions workflow in the Mini Shai-Hulud campaign; payload targets crypto wallet data.

Aikido Security; The Hacker News

29 April 2026

Four SAP npm packages compromised via leaked npm token in the Mini Shai-Hulud campaign.

Aikido Security

30 April 2026

PyTorch Lightning package compromised on PyPI as part of the same campaign.

Aikido Security

12 May 2026

TeamPCP open-sources the full Mini Shai-Hulud worm source code on GitHub under MIT License; simultaneously announces a $1,000 BreachForums contest for the largest supply chain attack using the code. Concurrently, the campaign expands to 160+ packages.

ReversingLabs; Tenable; Security Boulevard

15 May 2026

Additional Red Hat employee credentials detected in infostealer logs.

The Hacker News

19 May 2026

Microsoft's DurableTask npm package compromised in the Mini Shai-Hulud campaign.

Aikido Security

20 May 2026

Nine malicious Polymarket-branded npm packages published targeting crypto wallet keys.

SafeDep

24 May 2026

Socket reports TrapDoor campaign: 34+ malicious packages across npm, PyPI, and Crates.io targeting crypto and DeFi developers.

CyberLeveling

29 May 2026

First commit containing the 'Miasma: The Spreading Blight' string appears in RedHatInsights repositories.

The Hacker News

June 2026

Miasma attack executes in two waves (10:53 UTC and 13:44–13:46 UTC). Malicious commits pushed to RedHatInsights GitHub organization; 96 backdoored versions of 32 @redhat-cloud-services npm packages published with valid SLSA provenance attestations.

Wiz Blog; Orca Security; The Register

June 2026

Wiz Research publicly discloses the Miasma campaign. Red Hat removes affected packages from the npm registry and issues a statement that malicious code did not reach customer production systems.

The Register; BleepingComputer

3 June 2026

Cloud Security Alliance publishes research note on Miasma with extended technical analysis.

Cloud Security Alliance
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 25 of 25 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 6/15/2026, 5:42:54 PM

last updated: 8/15/2026, 4:52:42 AM

3 views

avoid.net — verified advice for a post-truth world