| A major npm supply-chain incident reportedly hit the @redhat-cloud-services scope, with 30+ packages pushed in backdoored versions carrying a self-propagating credential-stealing worm called Miasma ..which is believed to be the evolved version of Mini Shai-Hulud. The interesting part is the attack path. instead of relying on stolen npm tokens, the attackers abused an OIDC trusted publishing gap where npm validated the GitHub repo and workflow path but not the branch/ref. That allowed malicious packages to be published without any discrepancies. [link] [comments] |
Intelligence View
30+ Red Hat npm Packages Hijacked Through OIDC Trusted Publishing Gap
A major npm supply-chain incident reportedly hit the @redhat-cloud-services scope, with 30+ packages pushed in backdoored versions carrying a self-propagating credential-stealing worm called Miasma ..which is believed to be the evolved…
SOCIAL SHARE CARD GENERATOR