MEDIUMSupply Chain
Global
Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages
·Source: Snyk
Updated:
Executive Summary
A supply chain worm dubbed Miasma has been found in dozens of @redhat-cloud-services npm releases. The malicious preinstall hook steals credentials, probes cloud identities, and can republish other packages.
Analysis
A supply chain worm dubbed Miasma has been found in dozens of @redhat-cloud-services npm releases. The malicious preinstall hook steals credentials, probes cloud identities, and can republish other packages.