PulseAugur
EN
LIVE 17:53:49

Red Hat npm Miasma campaign steals credentials via 32 malicious packages

A credential-stealing campaign has been uncovered, involving 32 malicious npm packages that affected over 90 versions. These packages were designed to steal credentials, posing a significant security risk to users and systems that incorporated them. The campaign, dubbed 'Miasma,' specifically targeted the Red Hat ecosystem, highlighting vulnerabilities in software supply chains. AI

IMPACT Highlights supply chain vulnerabilities in software development, impacting the security of AI-related tools and infrastructure.

RANK_REASON This is a report on malicious software affecting a specific ecosystem, not a new model release or significant industry-wide event.

Read on Mastodon — mastodon.social →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

COVERAGE [1]

  1. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    🤖 Red Hat npm Miasma Credential-Stealing Campaign 📝 32 malicious npm packages affected over 90 versions, steal... https://www. microsoft.com/en-us/security/b lo

    🤖 Red Hat npm Miasma Credential-Stealing Campaign 📝 32 malicious npm packages affected over 90 versions, steal... https://www. microsoft.com/en-us/security/b log/2026/06/02/preinstall-persistence-inside-red-hat-npm-miasma-credential-stealing-campaign/ 📰 Microsoft Security Blog # …