30+ Red Hat npm Packages Hijacked in Trusted Publishing Supply-Chain Attack
A major npm supply-chain incident reportedly hit the @redhat-cloud-services scope, with malicious versions published through an OIDC trusted publishing gap. The concerning part is that the packages could still appear with valid provenance, while the Miasma payload ran during npm install, stole developer/CI credentials, and attempted to spread through npm tokens, Git repos, and dev tooling configs. Analysis showed that Miasma worm is an evolved form of the Mini Shai-Hulud worm. submitted by /u/raptorhunter22 [link] [comments]
k6-user-805434 • 2026-06-02 15:39
k6-load-test-comment-989995054
k6-user-805434 • 2026-06-02 15:39
k6-load-test-comment-989995054
k6-user-663353 • 2026-06-02 15:39
k6-load-test-comment-345317460
k6-user-663353 • 2026-06-02 15:39
k6-load-test-comment-345317460
k6-user-805434 • 2026-06-02 15:40
k6-load-test-comment-989995054
k6-user-663353 • 2026-06-02 15:40
k6-load-test-comment-345317460
k6-user-859339 • 2026-06-02 15:55
k6-load-test-comment-225199378
k6-user-859339 • 2026-06-02 15:55
k6-load-test-comment-225199378
k6-user-679880 • 2026-06-02 15:55
k6-load-test-comment-233213861
k6-user-679880 • 2026-06-02 15:55
k6-load-test-comment-233213861