Miasma Supply Chain Attack Hits Red Hat npm Packages
Hoplon InfoSec
02 Jun, 2026
Miasma Supply Chain Attack: Red Hat npm Breach Exposed
A trusted npm package can become dangerous before a developer even sees a warning. That is the real danger behind the Miasma supply chain attack, a 2026 npm malware campaign that hit Red Hat cloud service packages and targeted developer secrets.
This guide is written for students, developers, and security learners who want a clear breakdown of what happened, why it matters, and how this type of attack can spread through modern software pipelines.
What is the Miasma Supply Chain Attack?
The Miasma supply chain attack is a 2026 npm supply chain attack that compromised packages under the @redhat-cloud-services namespace. The malware used a malicious install-time script to steal credentials, cloud secrets, GitHub tokens, npm tokens, SSH keys, and CI/CD secrets. Researchers linked it to tactics used by Mini Shai-Hulud malware, including credential harvesting, encrypted data theft, and worm-like propagation through developer and CI/CD environments.
Key Technical Details
- Attack Name: Miasma
- Type: npm supply chain attack
- Target: @redhat-cloud-services npm packages
- Malware: Credential-stealing worm
- Related Family: Mini Shai-Hulud variant
- Attack Vector: Malicious npm install script
- Main Risks: Credential theft, cloud access theft, CI/CD compromise
- Affected Systems: npm, GitHub Actions, cloud environments, developer machines
- Reported: June 2026
- Possible Entry Point: Compromised Red Hat GitHub account
At a Glance
- Miasma compromised trusted Red Hat npm packages.
- The malware stole developer, cloud, and CI/CD credentials.
- Researchers linked its behavior to Mini Shai-Hulud.
- The attack likely started through a compromised GitHub account.
Security firms reported that multiple official-looking Red Hat Cloud Services npm packages were published with malicious versions. Some reports put the scope at 32 packages and 96 compromised versions, although exact counts should be verified against official advisories before publication.
The Miasma Supply Chain Attack is not just another malware headline. It shows how attackers can abuse trusted development tools to reach deeper into business systems.
Here is the short version:
- Attackers compromised npm packages linked to Red Hat Cloud Services.
- The malware behaved like a credential-stealing worm.
- It ran during package installation using a malicious preinstall hook.
- It targeted GitHub, npm, SSH, cloud, Kubernetes, Vault, and CI/CD secrets.
- It attempted to spread by abusing stolen credentials and development workflows.
- Researchers compared it to the Mini Shai-Hulud malware campaign.
- Removing the package alone may not be enough if secrets were already stolen.
For a student, this is a strong case study in software supply chain security. For a developer, it is a warning that dependency trust is no longer simple. For a company, it is a reminder that one developer machine compromise can become a larger business problem.
Why This Matters
The biggest issue is trust.
Most developers do not read every line of every npm dependency. They install packages, run builds, and move on. That normal workflow is exactly what this attack abused.
The Miasma Red Hat npm package incident matters because the affected packages came from a trusted namespace. That changes the psychology of the attack. A fake package with a strange name may look suspicious. A package under a familiar Red Hat-related scope feels safer.
That is the trap.
Our technical reading of this incident shows three major risks:
- Developers were targeted directly, not only production servers.
- CI/CD pipelines were part of the attack path, not just collateral damage.
- Cloud identity theft became a major focus, which can lead to broader access than a single stolen password.
This is why the Red Hat npm package compromise should be studied carefully. It is not only about npm. It is about how modern software teams build, publish, and deploy code.
Understanding Software Supply Chain Attacks
A software supply chain attack happens when attackers compromise something inside the software development or delivery process.
That “something” can be the following:
- A package dependency
- A maintainer account
- A GitHub repository
- A CI/CD workflow
- A build script
- A container image
- A package registry token
- A developer workstation
In this case, the focus was npm package distribution.
How npm Ecosystems Become Targets
npm is widely used in JavaScript and frontend development. It is fast, flexible, and massive. That also makes it attractive to attackers.
Common npm attack methods include:
- Publishing lookalike packages
- Taking over maintainer accounts
- Adding malicious lifecycle scripts
- Stealing npm tokens
- Poisoning package updates
- Abusing GitHub Actions publishing workflows
- Hiding obfuscated JavaScript inside normal packages
The Miasma supply chain attack shows why npm package security must include more than package name checks. A trusted namespace can still become risky if the publishing pipeline is compromised.
Timeline of the Miasma Attack
| Date | Event |
|---|---|
| April 13, 2026 |
Threat intelligence reporting later suggested a Red Hat GitHub credential may have appeared in infostealer logs. This should be treated as a possible lead, not final proof. |
| May 15, 2026 | Another Red Hat-related session cookie or credential exposure was reportedly observed in infostealer logs. |
| May 29, 2026 | Researchers noted early signs related to “Miasma: The Spreading Blight.” |
| June 1, 2026 | Multiple security firms publicly reported malicious Red Hat npm package activity. |
| After disclosure |
Teams were advised to isolate affected hosts, remove malicious versions, rotate credentials, and audit GitHub, npm, and CI/CD activity. |
Teams were advised to isolate affected hosts, remove malicious versions, rotate credentials, and audit GitHub, npm, and CI/CD activity.
How to Verify Exposure
A developer or student lab can start with these checks:
npm ls @redhat-cloud-services/vulnerabilities-client npm ls @redhat-cloud-services/rbac-client npm ls @redhat-cloud-services/sources-client
Also check lock files:
grep -R "@redhat-cloud-services" package-lock.json yarn.lock pnpm-lock.yaml
For CI/CD systems, check:
- GitHub Actions logs
- Build artefacts
- Package install timestamps
- npm publish logs
- Recently created GitHub workflows
- Recently changed .github/workflows/files
Important: Finding no package in node_modules today does not prove the system was never exposed. If the package was installed earlier, credentials may already have been collected.
Miasma vs Common NPM Malware
The key difference is intent and scale. Miasma was not just trying to steal one local file. It targeted the systems that build and ship software.