Industry
Dozens of Red Hat packages backdoored through its official NPM channel
On June 1, 2026, multiple official packages from the @redhat-cloud-services scope on NPM were compromised with a credential-stealing worm, affecting 96 versions across 32 packages totaling 116,991 wee
On June 1, 2026, multiple official packages from the @redhat-cloud-services scope on NPM were compromised with a credential-stealing worm, affecting 96 versions across 32 packages totaling 116,991 weekly downloads. A compromised Red Hat employee GitHub account was used to inject malware into these packages, with malicious commits bypassing code review. The malicious preinstall hooks execute a multi-stage credential stealer targeting AWS, Azure, GCP, HashiCorp Vault, Kubernetes, GitHub Actions OIDC, npm, Bitwarden, and 1Password.
Source: Ars Technica | 2026-06-01