www.microsoft.com 6/3/2026, 5:49:07 AM · external

Malicious npm packages breach RedHat CI/CD to steal secrets

Malicious npm packages breach RedHat CI/CD to steal secrets
CyberSIXT Evidence Panel Source marked as original reporting

MICROSOFT Threat Intelligence reports a significant npm supply chain attack affecting over 90 versions of 32 maliciously modified packages under the @redhat-cloud-services scope. The attackers compromised the CI/CD pipeline of RedHatInsights, allowing trojanized packages with authentic signatures to be published.

These packages executed a heavily obfuscated dropper script upon installation, downloading a secondary payload designed to steal credentials from various platforms such as GitHub, AWS, Azure, and Kubernetes. The malware targets secrets, uses privilege escalation techniques, and propagates across repositories while employing destruction mechanisms to wipe the victim’s home directory if necessary conditions are met. The attack impacts many developer environments, emphasizing the need for enhanced security measures.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline