📡 Breaking news
Analyzing latest trends...

Compromised Red Hat Account Infected 32 npm Packages with Shai-Hulud Malware.

Compromised Red Hat Account Infected 32 npm Packages with Shai-Hulud Malware.
Supply Chain Attack: 32 Red Hat npm Packages Infected with 'Shai-Hulud' Malware via GitHub Actions Exploit

Cloud security firm Wiz has uncovered a sophisticated software supply chain attack targeting Red Hat. Investigators revealed that 32 malicious npm packages under Red Hat’s official @redhat-cloud-services scope had been compromised and injected with info-stealing malware. Red Hat’s security team has since moved swiftly to unpublish and remove nearly all affected packages from the public npm registry.

The Payload: 'Shai-Hulud' Targets Cloud API Credentials

The embedded malware family has been identified as Shai-Hulud, a notorious strain engineered specifically for credential harvesting. Once an infected npm package is bundled into a developer's project or an enterprise application, the malware activates to scan the local environment, targeting high-value cloud API keys, including access tokens for Google Cloud Platform (GCP) and Microsoft Azure.

The Attack Vector: Compromised Credentials and CI/CD Hijacking

Forensics indicate that the breach originated from a targeted credential compromise rather than an architectural vulnerability within Red Hat's systems:

  1. Account Takeover: The threat actors successfully compromised the personal GitHub account of a Red Hat software engineer.

  2. Workflow Manipulation: Using this unauthorized access, the attackers pushed malicious code changes to a non-main branch within the RedHatInsights repository.

  3. Token Exfiltration: The modified code altered the automated GitHub Actions CI/CD workflows. This maneuver was explicitly designed to trigger a workflow run that scraped and exfiltrated highly sensitive npm automation tokens stored within GitHub's secrets vault.

  4. Malicious Publishing: Armed with these legitimate npm publishing credentials, the attackers bypassed standard code-review protocols and pushed malicious updated versions of the 32 packages directly to the public registry.

Remediation and Mitigation Strategies

While Red Hat has successfully expunged the compromised packages from the npm ecosystem, security firm Wiz warns that the blast radius could still impact downstream environments.

For organizations utilizing Red Hat cloud services components, Wiz urgently recommends a comprehensive security audit covering developer workstations, CI/CD pipelines, and internal source code repositories. As a defensive baseline, DevOps teams are strongly advised to rotate all cloud infrastructure keys and API tokens that may have been exposed during the active breach window.

Currently, many developers are complacent, believing that storing tokens in GitHub Secrets or Environment Variables is 100% secure. However, this case illustrates that if a hacker can modify the YAML file of a workflow (e.g., .github/workflows/build.yml) in a secondary branch, they can immediately instruct a script to echo or send those secret values ​​to an external server via a simple command like curl as soon as the CI/CD process starts. This is why the current trend is towards implementing Workflow Least Privilege, limiting access to secondary branches from the main secret.

Modern hackers don't directly try to penetrate an organization's thick firewall, but instead choose to target employees' "personal accounts" (e.g., through phishing or stealing session cookies). This is because employees often use overly broad access rights (over-privileged accounts). Once a hacker gains control of a single developer's account, they can use the reputation and credibility of a global brand like Red Hat as a springboard to spread malware to customers worldwide in a flash.

The malware's name, "Shai-Hulud," is derived from... The "giant sand worm" from the famous science fiction novel Dune, which burrows underground to devour anything that moves in the sand, is used as the name for this malware to reflect its behavior of silently lurking beneath the system, waiting to "harvest" crucial cloud API keys the moment code is moved or executed.

 

The $500 Million AI Bill Uncapped Claude Enterprise Tokens Shocked One Corporate Giant.

 

Source: Wiz 

💬 AI Content Assistant

Ask me anything about this article. No data is stored for your question.

Comments

Popular posts from this blog

Anthropic Secures $65 Billion Series H to Lock Down Global Chip Supply.

Pope Leo XIV Issues Landmark Encyclical on AI Aligning with Anthropic Co-Founder to Warn Against Transhumanism.

Xiaomi Slashes MiMo-V2.5-Pro API Fees by Half to Rival DeepSeek.

YouTube Deploys Automated Scanners to Flag AI Video Uploads Hardcoding Labels Onto Titles and Shorts.

Micron Joins the $1T Club Blasts Past Tesla with Historic 48-Day Valuation Sprint Driven by AI Demand.

Steam Deck OLED crosses $900

HP Q2 2026 Results Premium PC Shift Drives $14.4 Billion Revenue Despite Shipment Drops.