A large-scale npm supply chain attack compromised over 90 versions of @redhat-cloud-services packages, silently infecting CI/CD environments and developer systems. The malicious code steals credentials from GitHub, cloud platforms, and local machines, then spreads like a worm by republishing trusted…
The post Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign appeared first on IT Security News.