ended6월 1일· 1 sources

RedHat npm Publisher Compromised: Supply Chain Attack Impacts 32 Packages

RedHat npm 발행자 침해, 공급망 공격으로 32개 패키지 감염

Why it matters

This attack exploits a fundamental flaw in npm's OIDC trust model: when a legitimate publisher account is compromised, the malicious code inherits all the trust granted to that publisher. The incident impacts 32 packages sharing the same OIDC identity, and the malware's self-propagating design—injecting fake CodeQL workflows to harvest credentials—demonstrates how supply chain attacks can cascade across entire development ecosystems with minimal friction.

1
Sources
+0
24h
Growth
111d
Active
npm malwaresupply chainRedHat Cloud ServicesOIDCcredential theftCodeQL injection

Sources

Related Issues