Compromised Red Hat Account Infected 32 npm Packages with Shai-Hulud Malware.
Supply Chain Attack: 32 Red Hat npm Packages Infected with 'Shai-Hulud' Malware via GitHub Actions Exploit Cloud security firm Wiz has uncovered a sophisticated software supply chain attack targeting Red Hat . Investigators revealed that 32 malicious npm packages under Red Hat’s official @redhat-cloud-services scope had been compromised and injected with info-stealing malware. Red Hat’s security team has since moved swiftly to unpublish and remove nearly all affected packages from the public npm registry. The Payload: 'Shai-Hulud' Targets Cloud API Credentials The embedded malware family has been identified as Shai-Hulud , a notorious strain engineered specifically for credential harvesting. Once an infected npm package is bundled into a developer's project or an enterprise application, the malware activates to scan the local environment, targeting high-value cloud API keys, including access tokens for Google Cloud Platform (GCP) and Microsoft Azure . The Attack...