Slow Fog: Red Hat cloud service npm package suffers from active supply chain attacks, with stolen credentials found in over 300 GitHub repositories

By: rootdata|2026/06/02 15:42:57
0
Share
copy

SlowMist has issued a security alert, detecting an active npm supply chain attack targeting @redhat-cloud-services related packages. Currently, over 31 packages have been confirmed affected, with a weekly download volume of approximately 116,000 times, and stolen credentials exist in more than 300 GitHub repositories. This attack method is highly similar to the previous "Shai-Hulud" npm attack, including credential theft, creation of malicious repositories, and automated secret leakage. New suspicious repositories continue to emerge, indicating that the attack is still ongoing, and developers are still being continuously infected.

Potential harms include: theft of GitHub/npm tokens, leakage of AWS/GCP/Azure cloud credentials, collection of SSH keys and Kubernetes secrets, leakage of local environment and wallet data, creation of malicious repositories and persistence operations, and even potentially destructive actions after tokens are revoked. It is recommended to immediately remove or downgrade affected @redhat-cloud-services package versions, conduct a comprehensive audit of CI/CD workflows and dependency installations, rotate all GitHub, npm, cloud service, SSH, and wallet-related keys, retain logs, and rebuild exposed developer machines or Runners from clean images while maintaining a high level of vigilance.

You may also like

Collective Change of Ownership for Crypto Exchanges? The Positioning Competition Among South Korean Financial Giants

Securities firms and banks work together to reposition the landscape of cryptocurrency in South Korea.

a16z Crypto's latest article: Why do we need to predict the market?

It turns people's judgments about the future into tradable probabilities. It has advantages in both predictive accuracy and coverage that traditional polls find hard to match, but whether it can realize its potential depends on whether it can solve the design challenges of transparency, insider info...

Strategy cashes out 2.5 million USD, but Bitcoin's market value dropped by 80 billion USD in one day

The market's reliance on this narrative of hoarding coins is more fragile than many people imagine.

WEEXPERIENCE Trading Bootcamp in Poland: How WEEX & FireCrew Are Making Crypto Trading Accessible to Everyone

WEEX partnered with Firecrew in Poland on May 29th for the WEEXPERIENCE trading bootcamp. Read the recap of expert sessions on technical analysis, trading psychology, and AI tools that prove WEEX’s mission to make crypto trading accessible to everyone.

Paris Reigns Supreme: How PSG Crushed Arsenal’s Dream in a Historic UCL Final Thriller

PSG vs Arsenal, Drama, destiny, and a shattered 20-year curse. Relive the 2026 UCL Final where PSG defended their crown in a tense penalty shootout, as Ousmane Dembélé’s golden moment and one agonizing miss wrote history in Budapest.

Full text and analysis of the speech by the CEO of SanDisk at the 42nd Annual Strategic Decision Conference of Bernstein

The core value of Goeckeler's speech lies in its provision of a highly transparent and logically clear narrative framework for corporate transformation.

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com