Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    FedEx Freight CEO says the spinoff will help the company ‘leapfrog’ competitors

    June 2, 2026

    Chemring stock down after profit decline offsets record order book

    June 2, 2026

    Dozens of Red Hat packages backdoored through its official NPM channel

    June 2, 2026
    Facebook X (Twitter) Instagram
    Addison Markets
    • Home
    • USA
    • Europe
    • Business
    • Investing
    • Tech
    • Politics
    • Contact Us
    Addison Markets
    Home»Tech»Dozens of Red Hat packages backdoored through its official NPM channel
    Tech

    Dozens of Red Hat packages backdoored through its official NPM channel

    franperez66q@protonmail.comBy franperez66q@protonmail.comJune 2, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email



    The worm, dubbed Shai-Hulud, has all the hallmarks of malware released last month as freely available open source. TeamPCP was the first group to use Shai-Hulud, and it promoted a competition that promised a $1,000 payment to the hacker who carried out the biggest supply-chain attack using the malware. TeamPCP has also been behind a rash of previous supply-chain attacks. Now that the worm is in the hands of many other threat groups, supply-chain attacks may ramp up further.

    The malware devotes considerable attention to CI/CD (continuous integration/continuous delivery) systems, which allow for faster and more reliable software releases by automating the building, testing, and deploying of code changes. The malware spread in Monday’s attack was published through GitHub Actions OIDC (OpenID Connect), indicating that Red Hat’s CI/CD pipeline was compromised. OIDC is a security measure designed to interact with cloud services through the use of temporary credentials.

    Once installed, the malware targets other organizations’ CI/CD credentials. The compromise of Red Hat’s GitHub Actions OIDC was very possibly the result of a previous supply-chain attack that infected an employee’s machine.

    In an email sent after this post went live, Red Hat said it has removed the malicious packages.

    “The packages are strictly limited to internal development, and the malicious code was never published for customer consumption via the console.redhat.com system,” the email said. “While our investigation is ongoing, we have not identified any impact to customer or partner environments or Red Hat production systems.”

    Given the success of other recent supply-chain attacks, anyone who touched one of the affected packages in the past 36 hours should assume compromise of their workstations, CI/CD pipelines, and all credentials for cloud services and repositories. That means employees should drop whatever they’re doing at the moment and investigate thoroughly.

    In a recent supply-chain attack that hit Checkmarx, the security firm failed to fully drive out the party responsible. Checkmarx was then hit two more times. The Checkmarx credentials used in the first attack came from a supply chain attack on the Trivy software developer. The pivot to Checkmarx and its failure to fully remediate the initial breach demonstrates the difficulty of completely recovering from such security lapses and the risks that result.

    Both Socket and Aikido have lists of affected Red Hat packages and other indicators of compromise that any potentially affected person or organization should make use of promptly.

    Story updated to add Red Hat comment.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    franperez66q@protonmail.com
    • Website

    Related Posts

    Microsoft’s Surface Laptop Ultra looks like its first true MacBook Pro competitor

    June 2, 2026

    Jim Cramer says this company’s spin-off could unlock significant upside

    June 2, 2026

    Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts

    June 2, 2026

    Nvidia’s entrance into the PC market gives investors another reason to own the stock

    June 2, 2026

    Moderna gets $50 million to develop mRNA Ebola vaccine against Bundibugyo

    June 2, 2026

    Jim Cramer says Jensen Huang’s Computex keynote revealed more winners in the AI boom

    June 2, 2026
    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    FedEx Freight CEO says the spinoff will help the company ‘leapfrog’ competitors

    June 2, 2026

    Chemring stock down after profit decline offsets record order book

    June 2, 2026

    Dozens of Red Hat packages backdoored through its official NPM channel

    June 2, 2026

    Abivax stock sinks over 30% after bowel disease drug trial update

    June 2, 2026
    © 2026 All right reserved
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.