ended6월 2일· 1 sources
Red Hat's Official NPM Channel Weaponized in Massive Supply Chain Attack
Red Hat 공식 NPM 채널 장악당해 자격증명 탈취 악성코드 확산
Why it matters
This attack is particularly dangerous because it exploits the implicit trust developers place in official Red Hat packages—bypassing their security assumptions entirely. The malware executes during installation, meaning developers and their systems are compromised before they even use the code, creating widespread exposure. With the worm capable of stealing credentials and spreading to additional systems and repositories, organizations must assume any affected machine is fully compromised.
1
Sources
+0
24h
—
Growth
3d
Active
Supply chain attacknpm packagesCredential theftMalware wormRed Hat