๐จ Breaking: 31 npm packages from
@RedHat have been compromised.
100,000+ weekly downloads affected. The upstream CI/CD pipeline was compromised, with all packages published via GitHub Actions OIDC.
The payload:
โ ๏ธ Reads GitHub Actions runner process memory to extract masked secrets
โ ๏ธ Sweeps credentials across AWS, GCP, Azure, K8s, Vault, and npm
โ ๏ธ Self-propagating worm that republishes backdoored packages using stolen npm tokens, bypassing 2FA
โ ๏ธ Persists on dev machines via Claude Code settings hijack and VS Code task injection
โ ๏ธ Exfiltrates data through GitHub API commits, blending in with normal git operations
We have responsibly disclosed the incident to the maintainers.
Full technical analysis: