[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhf8vyLQTiOpjOD8Vv1H73vDEL1PvFw-gCOueBWdr2EA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"088bddba-2e48-4552-a631-7cb38baa7859","supply-chain-attack-targets-red-hat-npm-packages-with-credential-stealing-malware","f3594485-3e2d-4a58-8804-9887576c3a50","Supply Chain Attack Targets Red Hat npm Packages with Credential-Stealing Malware","Attackers compromised Red Hat Cloud Services npm packages by injecting malicious code into preinstall lifecycle hooks that executed obfuscated malware designed to steal sensitive credentials and secrets. The attack leveraged the Shai-Hulud toolkit's tactics, demonstrating how publicly available malware tools lower the barrier for threat actors to conduct sophisticated supply chain attacks. This incident highlights the critical vulnerability of the JavaScript ecosystem to package-based attacks that can compromise developer environments and steal valuable authentication tokens and cloud credentials.","**Immediate actions:**\n- Audit all npm packages in use and remove or replace any affected Red Hat Cloud Services packages\n- Rotate all potentially compromised credentials including GitHub tokens, cloud credentials, and CI\u002FCD secrets\n- Implement package integrity verification using npm audit and package-lock.json validation\n\n**Long-term improvements:**\n- Establish a software bill of materials (SBOM) process to track all third-party dependencies\n- Configure automated dependency scanning tools to detect malicious packages before installation\n- Implement package approval workflows that require security review for new dependencies\n\n**Detection measures:**\n- Monitor network traffic for unusual data exfiltration patterns from development environments\n- Set up alerts for unexpected preinstall script executions in package installations\n- Deploy endpoint detection tools to identify obfuscated script execution in developer workstations",[12,13,14,15,16,17],"CIS Control 2","NIST SP 800-161","NIST SP 800-53 SA-12","SLSA Framework","CIS Control 7","NIST SP 800-53 SI-7","published","2026-06-01T16:08:01.632628+00:00","2026-06-01T16:08:01.334+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fmini-shai-hulud-campaign-hits-red-hat-cloud-services-npm-packages?utm_medium=feed","mini-shai-hulud-campaign-hits-red-hat-cloud-services-npm-packages-3a195b","Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":33,"name":34,"slug":35,"description":36,"color":37},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]