Red Hat npm Packages Hit by Active Supply Chain Attack; 300+ GitHub Repos Contain Stolen Credentials on June 2

According to SlowMist, on June 2, an active npm supply chain attack targeting @redhat-cloud-services packages was detected. The attack has compromised 31+ packages with approximately 116,000 weekly downloads, and stolen credentials were found in over 300 GitHub repositories. The attack method mirrors the previous "Shai-Hulud" npm campaign, involving credential theft, malicious repository creation, and automated secret exfiltration. New suspicious repositories continue to emerge, indicating the attack is ongoing.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments