arstechnica.com 6/1/2026, 8:21:10 PM · external

Red Hat NPM accounts hacked, Shai-Hulud worm steals credentials

Red Hat NPM accounts hacked, Shai-Hulud worm steals credentials
CyberSIXT Evidence Panel
Primary Source aikido.dev

RED Hat's official NPM accounts were compromised, leading to a malicious worm, named Shai-Hulud, affecting over 30 packages. This worm collects sensitive credentials during the npm install process and spreads by republishing backdoored packages. Investigations suggest the breach stemmed from compromised credentials, possibly from a previous supply-chain attack. Organizations that installed the affected packages in the last 36 hours are advised to consider their systems potentially compromised.

The malware specifically targets CI/CD systems and can publish stolen credentials to compromised GitHub repositories. Immediate action is recommended for affected entities to assess and mitigate the damage.

View Primary Source Via arstechnica.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline