Minacce · 111 giorni fa
Un package npm firmato può comunque essere una trappola se la pipeline CI/CD o l'account del maintainer sono compromessi. La rottura non è solo una dipendenza difettosa; il percorso di publishing trusted stesso può essere usato per distribuire veleno che continua a sembrare legittimo agli strumenti di verification.
13 fonti che coprono questa storia
Shai-Hulud malware worms Red Hat npm package versions downloaded 80K times a week
TeamPCP? Or copycat malware dev?
IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks
Multiple npm supply chain attacks used 50+ poisoned packages to spread IronWorm, a Rust-based stealer, and a Miasma worm variant.
Rust-Written IronWorm Hits NPM Supply Chain
Like Shai-Hulud, the campaign targets developers to steal credentials and reuses them to propagate across the software supply channel.
New IronWorm malware hits 36 packages in npm supply-chain attack
A new supply-chain attack has infected 36 packages on the Node Package Manager (npm) index with infostealer malware called IronWorm.
The malicious code steals credentials from GitHub, cloud platforms, and local machines, then spreads like a worm by republishing trusted packages.
Dozens of Red Hat npm packages targeted in supply chain attack
Researchers said a variant of the Mini Shai-Hulud is involved in the compromise.
The Record from Recorded Future
Red Hat removes tainted packages after software pipeline compromise
According to the company’s preliminary analysis, a compromised GitHub account was used to push the malicious code out to customers, hitting 32 packages downloaded roughly 117,000 times a week.
Shai Hulud returns wearing a Red Hat
Researchers have uncovered a new Shai-Hulud malware variant hiding in Red Hat npm packages that now also gathers Google Cloud and Azure identities, an addition to its previous credential-snatching behavior.
Attackers Hijack Red Hat npm Scope to Steal Cloud Secrets
Attackers backdoored 32 packages in Red Hat's official npm scope to steal cloud and CI secrets
Supply Chain Attack Hits 32 Red Hat NPM Packages
Hackers published 96 malicious package versions, injected with a credential-stealing worm similar to Mini Shai-Hulud.
Red Hat npm packages compromised in new Mini Shai-Hulud malware wave - Help Net Security
Unknown attackers have compromised 30+ Red Hat Cloud Services npm packages with malware that goes after developers' secrets.
Red Hat npm packages compromised to steal developer credentials
More than 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were compromised in a supply-chain attack that distributed a new variant of the Shai-Hulud credential-stealing malware, dubbed "Miasma."
Part of the PlainSec briefing for 2026-05-30