HIGH • SecOpsAI Intelligence

Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign

A large-scale npm supply chain attack compromised over 90 versions of @redhat-cloud-services packages, silently infecting CI/CD environments and developer systems. The malicious code steals credentials from GitHub, cloud platforms, and local machines, then spreads like a worm by republishing trusted packages. Discover how the attack works, what data is at risk, and the steps you can take to protect your organization. The post Preinstall to persistence: Inside the Red Hat npm Miasma credential-st

High By Microsoft Security Blog 1 min read Published: Wed, 03 Ju Updated: 2026-06-04
Security News Threat Intelligence npm github supply-chain attack
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign
Source: Microsoft Security Blog

Source Metadata

Why It Matters

  • Source type: Threat Intelligence
  • Severity hint: high (Compromise, credential-theft, malware, or supply-chain signal.)
  • Extracted signals: supply-chain attack

What SecOpsAI Can Detect

SecOpsAI can help operators review token exposure, credential-rotation tasks, CI/CD workflow risk, and SOC findings related to secret leakage or suspicious authentication activity.

Extracted Intelligence

CVEs

  • None found deterministically; reviewer should confirm source details.

Affected Packages Or Products

  • npm

IOCs

  • None found deterministically; reviewer should add source-backed indicators if present.

Recommended Actions

  • Rotate affected tokens or credentials if exposure is plausible.
  • Review GitHub Actions, OIDC trust relationships, OAuth grants, and cloud roles.
  • Check audit logs for suspicious use of impacted credentials or identities.
  • Tighten token scopes and remove stale non-human identities where possible.
  • Review extracted package references: npm.

Operator Commands

secopsai triage summary
secopsai research preflight
secopsai supply-chain advisory list
secopsai blog news-review show news-351daec4f3181d58-preinstall-to-persistence-inside-the-red-hat-npm-miasma-credential-s

References

Comments

Comments are moderated before publication. Do not post secrets, tokens, customer data, or exploit payloads.