Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Miasma Attack Targets Red Hat npm Packages with Worm

Miasma Attack Targets Red Hat npm Packages with Worm

Posted on June 1, 2026 By CWS

A recent cybersecurity threat, labeled as the Miasma attack, has compromised specific Red Hat npm packages. This campaign aims to steal sensitive credentials and distribute a self-replicating worm across developer environments.

Key Tactics of the Miasma Campaign

The Miasma attack mirrors previous Mini Shai-Hulud strategies by executing during installation, harvesting credentials, and targeting CI/CD systems. It utilizes encrypted exfiltration methods and can potentially propagate further down the supply chain, according to cybersecurity firm Socket.

The individuals orchestrating this attack remain anonymous. However, the open-sourcing of attack tools by the cybercrime group TeamPCP has made it difficult to pinpoint the responsible parties, as these tools are now accessible to various threat actors.

Affected Packages and Attack Mechanics

The compromised packages include @redhat-cloud-services/vulnerabilities-client and others. Security analyses from several firms revealed an obfuscated preinstall hook within these packages, designed to extract cloud credentials, SSH keys, and other confidential information.

The malware uses encrypted channels to transmit stolen data to an external server and employs GitHub as a backup for data transmission. It avoids activation on systems running in Russian, a tactic seen in previous campaigns.

Implications and Security Recommendations

This attack highlights a shift in focus towards cloud identity theft, with new data collectors added for GCP and Azure environments. The malware’s ability to create unique encrypted payloads for each infection complicates detection and version tracking.

Initial findings suggest the attack originated from a compromised Red Hat employee GitHub account. To mitigate the impact, experts advise isolating affected hosts, removing malicious package versions, and rotating compromised credentials.

Additionally, a thorough audit of environments for persistent elements and suspicious activities in GitHub or npm is crucial. Strong access controls and a review of deployed artifacts are recommended to ensure system integrity.

In conclusion, while uninstalling affected packages may seem like a solution, the persistence mechanisms employed by this malware require a more comprehensive approach to secure affected systems effectively.

The Hacker News Tags:CI/CD, cloud security, credential theft, Cybersecurity, developer security, Encryption, Exfiltration, GitHub, Malware, Miasma, NPM, Red Hat, software vulnerabilities, supply chain attack, Threat Actors

Post navigation

Previous Post: Critical IBM WebSphere Flaw Risks Remote Code Execution
Next Post: Critical WP Maps Pro Flaw Endangers WordPress Sites

Related Posts

CISA Highlights Critical Linux Vulnerability Exploitation CISA Highlights Critical Linux Vulnerability Exploitation The Hacker News
EncryptHub Targets Web3 Developers Using Fake AI Platforms to Deploy Fickle Stealer Malware EncryptHub Targets Web3 Developers Using Fake AI Platforms to Deploy Fickle Stealer Malware The Hacker News
Russian Hackers Create 4,300 Fake Travel Sites to Steal Hotel Guests’ Payment Data Russian Hackers Create 4,300 Fake Travel Sites to Steal Hotel Guests’ Payment Data The Hacker News
Microsoft Addresses High-Severity Windows Admin Center Flaw Microsoft Addresses High-Severity Windows Admin Center Flaw The Hacker News
Why IT Leaders Must Rethink Backup in the Age of Ransomware Why IT Leaders Must Rethink Backup in the Age of Ransomware The Hacker News
Chrome Targeted by Active In-the-Wild Exploit Tied to Undisclosed High-Severity Flaw Chrome Targeted by Active In-the-Wild Exploit Tied to Undisclosed High-Severity Flaw The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI-Powered Malware Adapts to Security Measures
  • McKesson Faces Data Breach Amid Extortion Threat
  • Aurora Ransomware Leveraging AI in Cyber Attacks
  • OpenClaw 2.0 Launches with Enhanced Security Features
  • AI Security Threats Highlighted by Hugging Face Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI-Powered Malware Adapts to Security Measures
  • McKesson Faces Data Breach Amid Extortion Threat
  • Aurora Ransomware Leveraging AI in Cyber Attacks
  • OpenClaw 2.0 Launches with Enhanced Security Features
  • AI Security Threats Highlighted by Hugging Face Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark