ended6월 1일· 1 sources
Self-Propagating Worm Infects Red Hat's npm Supply Chain, Steals Cloud Credentials
Red Hat npm 공급망 침투한 자가증식 악성코드, 클라우드 자격증명 탈취
Why it matters
This attack bypasses traditional defenses by compromising legitimate packages from a trusted vendor—developers who trust Red Hat's official npm scope have no protection against this vector. The malware's self-replication exploits stolen npm tokens to automatically spread across installations, while harvested cloud and CI/CD credentials enable complete infrastructure takeover. Persistence mechanisms embedded in editor configuration files indicate attackers designed this for long-term, multi-stage exploitation.
1
Sources
+0
24h
—
Growth
102d
Active
npm compromiseRed Hatcredential theftself-propagating wormCI/CD sabotage