Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
Codenamed Miasma, a new Mini Shai-Hulud supply chain assault campaign has infiltrated @redhat-cloud-services packages to transmit a self-propagating worm and steal credentials and secrets from developer machines.
Because it employs the same fundamental strategies of install-time execution, credential harvesting, CI/CD targeting, encrypted exfiltration, and possible downstream propagation, this is essentially a Mini Shai-Hulud campaign, according to Socket.
Since TeamPCP, a notorious cybercrime group, has made the attack tools associated with the Shai-Hulud worm publicly available, it is now difficult to pinpoint the exact perpetrator of the attack.
list of some of the impacted packages' names read more about Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credent...

