All updates
Written by Jun 3, 2026

security: Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign

Jun 3, 2026

Microsoft reports a large-scale npm supply chain attack affecting over 90 versions of @redhat-cloud-services packages. The malicious code targets CI/CD and developer systems to steal GitHub, cloud, and local credentials, and propagates by republishing trusted packages.

Sponsored by GitAds