ended6월 1일· 1 sources
RedHat npm Publisher Compromised: Supply Chain Attack Impacts 32 Packages
RedHat npm 발행자 침해, 공급망 공격으로 32개 패키지 감염
Why it matters
This attack exploits a fundamental flaw in npm's OIDC trust model: when a legitimate publisher account is compromised, the malicious code inherits all the trust granted to that publisher. The incident impacts 32 packages sharing the same OIDC identity, and the malware's self-propagating design—injecting fake CodeQL workflows to harvest credentials—demonstrates how supply chain attacks can cascade across entire development ecosystems with minimal friction.
1
Sources
+0
24h
—
Growth
111d
Active
npm malwaresupply chainRedHat Cloud ServicesOIDCcredential theftCodeQL injection