Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

Attackers compromised a Red Hat employee’s GitHub account and used it to inject credential-stealing malware into 32 npm packages under the official ‘@redhat-cloud-services’ namespace, collectively downloaded approximately 117,000 times per week. The malware, tracked as Miasma, targets cloud provider credentials, CI/CD pipeline tokens, SSH keys, and developer secrets, meaning any build environment that installed affected packages may have already exfiltrated sensitive access material. Organizations using these packages in AWS, Google Cloud, Azure, Kubernetes, or GitHub Actions pipelines face potential unauthorized cloud account access, data exfiltration, and lateral movement across their entire infrastructure.

Author

Tech Jacks Solutions