Miasma Campaign Infects Red Hat npm Packages
Latest supply chain attack reveals persistent threat of credential theft

Developers sourcing from the @redhat-cloud-services npm namespace encountered a worm instead of functional packages. Wiz researchers tracked the campaign, named Miasma, which compromised over 30 npm packages linked to Red Hat Cloud Services to exfiltrate credentials and secrets. The attack is an evolution of the Shai-Hulud malware, notorious for targeting the npm ecosystem.
Unauthorized modifications were discovered in 32 package releases, averaging 80,000 weekly downloads. This exposure affects a trusted software ecosystem, compelling organizations to assess potential breaches. Most compromised packages have since been removed.
The malware, a variant of Mini Shai-Hulud, is designed to steal npm tokens, environment variables, and cloud credentials. Cosmetic changes transform its theme from Dune to Greek mythology, but its core functionality remains lethal.
The campaign aimed for persistence within software distribution channels. It sought credentials linked to package publishing to expand its reach. Attackers manipulated workflows to mask malicious releases as legitimate, using GitHub Actions and OIDC tokens to generate trusted metadata.
Affected organizations should check for installations of tainted packages and rotate compromised secrets. Revoking npm publishing tokens and auditing publishing activities are critical steps. Wiz has published a list of indicators of compromise to aid in remediation.



