Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages
CYBERSECURITY FEATURED ANALYSIS

Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages

SOURCE

Blog RSS Feed | Snyk

DATE

READ

1 min read

A supply chain worm dubbed Miasma has been found in dozens of @redhat-cloud-services npm releases. The malicious preinstall hook steals credentials, probes cloud identities, and can republish other packages.

A supply chain worm dubbed Miasma has been found in dozens of @redhat-cloud-services npm releases. The malicious preinstall hook steals credentials, probes cloud identities, and can republish other packages.