NEWS Urgently change the keys: Red Hat was at the center of an attack on the supply chain through NPm

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,227
Immediately 95 official packages suddenly turned into spies.
1780389101186.png
Developers are accustomed to trust packages from the usual namespaces, especially when it comes to the components of large vendors. But a new incident with npm has shown that even such dependence can become the entry point to steal secrets. This time, malicious versions appeared among the Npm-components of the Red Hat Cloud Services space, and the attack itself reminded a reduced copy of the Shai-Hulud campaign.

The Socket team reported a malicious campaign against @redhat-cloud-services packages in npm. According to experts, the infected versions ran the hidden load through preinvesting huk, so the code was triggered automatically during the installation of dependence, even before its import into the project.

Dozens of Red Hat Cloud Services packages hit, including chrome, frontend-components, insights-client, rbac-client, host-inventory-client, compliance-client, questionnaires-client and others. In total, Socket tracks 95 affected artifacts published on June 1, 2026.

The analysis showed that index.js in the infected packages was disguised as an ordinary entry point, but actually ran a ostecasted bootloader. The code deciphered the built-in fragments via AES-GM, recorded the main load into the temporary file, ran it through Bun, and then deleted the traces. If Bun was absent, the malware itself tried to download the execution environment from GitHub.

The load collected the secrets of GitHub Actions, npm tokens, SSH keys, Git data, AWS, Azure and GCP cloud accounts, Kubernetes configurations, Vault secrets, Docker data and other sensitive files. The individual modules were aimed at the GitHub CLI and the memory of the GitHub Actions runners, where automation tokens could be located.

Socket also found an encrypted shipment of stolen data through HTTPS and a backup channel via the GitHub API. If there is a suitable malware token, could record in the JSON repository with collection results. The code found signs of possible further distribution through the change of repositories and workflow-files.

The authors of the report associate the attack technique with the approaches of Shai-Hulud, but do not call a specific operator. The appearance of TeamPCP’s open tools associated with Shai-Hulud reduces the entry threshold and allows different groups to repeat similar operations.

Organizations that have installed the affected versions are advised to consider such systems potentially compromised. Simply removing node_modules is not enough, since the malware could work in the background, change the configurations and steal secrets already during installation.

First of all, you need to check lock-files, CI/CD magazines, packages, developer workstations and assembly environments, and then re-released GitHub, npm tokens, cloud providers, Kubernetes, Vault, Docker, PyPI and SSH keys.
 

darkwebhutmanmecico

Member
Member
Joined
Jul 24, 2026
Messages
14
Reaction score
0
Immediately 95 official packages suddenly turned into spies.
View attachment 272
Developers are accustomed to trust packages from the usual namespaces, especially when it comes to the components of large vendors. But a new incident with npm has shown that even such dependence can become the entry point to steal secrets. This time, malicious versions appeared among the Npm-components of the Red Hat Cloud Services space, and the attack itself reminded a reduced copy of the Shai-Hulud campaign.

The Socket team reported a malicious campaign against @redhat-cloud-services packages in npm. According to experts, the infected versions ran the hidden load through preinvesting huk, so the code was triggered automatically during the installation of dependence, even before its import into the project.

Dozens of Red Hat Cloud Services packages hit, including chrome, frontend-components, insights-client, rbac-client, host-inventory-client, compliance-client, questionnaires-client and others. In total, Socket tracks 95 affected artifacts published on June 1, 2026.

The analysis showed that index.js in the infected packages was disguised as an ordinary entry point, but actually ran a ostecasted bootloader. The code deciphered the built-in fragments via AES-GM, recorded the main load into the temporary file, ran it through Bun, and then deleted the traces. If Bun was absent, the malware itself tried to download the execution environment from GitHub.

The load collected the secrets of GitHub Actions, npm tokens, SSH keys, Git data, AWS, Azure and GCP cloud accounts, Kubernetes configurations, Vault secrets, Docker data and other sensitive files. The individual modules were aimed at the GitHub CLI and the memory of the GitHub Actions runners, where automation tokens could be located.

Socket also found an encrypted shipment of stolen data through HTTPS and a backup channel via the GitHub API. If there is a suitable malware token, could record in the JSON repository with collection results. The code found signs of possible further distribution through the change of repositories and workflow-files.

The authors of the report associate the attack technique with the approaches of Shai-Hulud, but do not call a specific operator. The appearance of TeamPCP’s open tools associated with Shai-Hulud reduces the entry threshold and allows different groups to repeat similar operations.

Organizations that have installed the affected versions are advised to consider such systems potentially compromised. Simply removing node_modules is not enough, since the malware could work in the background, change the configurations and steal secrets already during installation.

First of all, you need to check lock-files, CI/CD magazines, packages, developer workstations and assembly environments, and then re-released GitHub, npm tokens, cloud providers, Kubernetes, Vault, Docker, PyPI and SSH keys.
 

CJNGCARTEL

Well-known member
Member
Joined
Jul 26, 2026
Messages
226
Reaction score
20
Immediately 95 official packages suddenly turned into spies.
View attachment 272
Developers are accustomed to trust packages from the usual namespaces, especially when it comes to the components of large vendors. But a new incident with npm has shown that even such dependence can become the entry point to steal secrets. This time, malicious versions appeared among the Npm-components of the Red Hat Cloud Services space, and the attack itself reminded a reduced copy of the Shai-Hulud campaign.

The Socket team reported a malicious campaign against @redhat-cloud-services packages in npm. According to experts, the infected versions ran the hidden load through preinvesting huk, so the code was triggered automatically during the installation of dependence, even before its import into the project.

Dozens of Red Hat Cloud Services packages hit, including chrome, frontend-components, insights-client, rbac-client, host-inventory-client, compliance-client, questionnaires-client and others. In total, Socket tracks 95 affected artifacts published on June 1, 2026.

The analysis showed that index.js in the infected packages was disguised as an ordinary entry point, but actually ran a ostecasted bootloader. The code deciphered the built-in fragments via AES-GM, recorded the main load into the temporary file, ran it through Bun, and then deleted the traces. If Bun was absent, the malware itself tried to download the execution environment from GitHub.

The load collected the secrets of GitHub Actions, npm tokens, SSH keys, Git data, AWS, Azure and GCP cloud accounts, Kubernetes configurations, Vault secrets, Docker data and other sensitive files. The individual modules were aimed at the GitHub CLI and the memory of the GitHub Actions runners, where automation tokens could be located.

Socket also found an encrypted shipment of stolen data through HTTPS and a backup channel via the GitHub API. If there is a suitable malware token, could record in the JSON repository with collection results. The code found signs of possible further distribution through the change of repositories and workflow-files.

The authors of the report associate the attack technique with the approaches of Shai-Hulud, but do not call a specific operator. The appearance of TeamPCP’s open tools associated with Shai-Hulud reduces the entry threshold and allows different groups to repeat similar operations.

Organizations that have installed the affected versions are advised to consider such systems potentially compromised. Simply removing node_modules is not enough, since the malware could work in the background, change the configurations and steal secrets already during installation.

First of all, you need to check lock-files, CI/CD magazines, packages, developer workstations and assembly environments, and then re-released GitHub, npm tokens, cloud providers, Kubernetes, Vault, Docker, PyPI and SSH keys.
Hello Hello to the cartels Hello, joining cartels Hello to those who want to join the cartels. Hello, those who want to join cartels, get involved in crime. Hello, those who want to join cartels, get involved in crime. Hello, those who want to join cartels, those who want to participate in crime, CJNG. Hello, those who want to join cartels, those who want to participate in crime, CJNG is looking for members. Hello, those who want to join cartels, those who want to participate in crime, CJNG is looking for members, join now. Hello, those who want to join cartels, those who want to participate in crime, CJNG is looking for members. If you'd like to join... Hello, those who want to join cartels, those who want to participate in crime, CJNG is looking for members. If you want to join, contact us. Hello, those who want to join cartels, those who want to participate in crime, CJNG is looking for members. If you want to join, contact us on Telegram. Hello, CJNG is looking for members for those who want to join cartels and participate in crime. If you are interested in joining, please contact us on Telegram. Hello, those who want to join cartels, those who want to participate in crime, CJNG is looking for members. If you want to join, contact us on Telegram. Hello, CJNG is looking for members for those who want to join cartels and participate in crime. If you are interested in joining, contact us on Telegram. There is a membership fee. Hello, CJNG is looking for members for those who want to join cartels and participate in crime. If you are interested in joining, contact us on Telegram. The membership fee is 70. Hello, CJNG is looking for members for those who want to join cartels and participate in crime. If you'd like to join, contact us on Telegram. The membership fee is $70. Hello, CJNG is looking for members for those who want to join cartels and participate in crime. If you'd like to join, contact us on Telegram. The membership fee is $70.

@Cipher5Network

 

BLACK VEIL

Well-known member
Member
Joined
Jul 29, 2026
Messages
56
Reaction score
27
Location
ABD
Website
www.shopier.com
Immediately 95 official packages suddenly turned into spies.
View attachment 272
Developers are accustomed to trust packages from the usual namespaces, especially when it comes to the components of large vendors. But a new incident with npm has shown that even such dependence can become the entry point to steal secrets. This time, malicious versions appeared among the Npm-components of the Red Hat Cloud Services space, and the attack itself reminded a reduced copy of the Shai-Hulud campaign.

The Socket team reported a malicious campaign against @redhat-cloud-services packages in npm. According to experts, the infected versions ran the hidden load through preinvesting huk, so the code was triggered automatically during the installation of dependence, even before its import into the project.

Dozens of Red Hat Cloud Services packages hit, including chrome, frontend-components, insights-client, rbac-client, host-inventory-client, compliance-client, questionnaires-client and others. In total, Socket tracks 95 affected artifacts published on June 1, 2026.

The analysis showed that index.js in the infected packages was disguised as an ordinary entry point, but actually ran a ostecasted bootloader. The code deciphered the built-in fragments via AES-GM, recorded the main load into the temporary file, ran it through Bun, and then deleted the traces. If Bun was absent, the malware itself tried to download the execution environment from GitHub.

The load collected the secrets of GitHub Actions, npm tokens, SSH keys, Git data, AWS, Azure and GCP cloud accounts, Kubernetes configurations, Vault secrets, Docker data and other sensitive files. The individual modules were aimed at the GitHub CLI and the memory of the GitHub Actions runners, where automation tokens could be located.

Socket also found an encrypted shipment of stolen data through HTTPS and a backup channel via the GitHub API. If there is a suitable malware token, could record in the JSON repository with collection results. The code found signs of possible further distribution through the change of repositories and workflow-files.

The authors of the report associate the attack technique with the approaches of Shai-Hulud, but do not call a specific operator. The appearance of TeamPCP’s open tools associated with Shai-Hulud reduces the entry threshold and allows different groups to repeat similar operations.

Organizations that have installed the affected versions are advised to consider such systems potentially compromised. Simply removing node_modules is not enough, since the malware could work in the background, change the configurations and steal secrets already during installation.

First of all, you need to check lock-files, CI/CD magazines, packages, developer workstations and assembly environments, and then re-released GitHub, npm tokens, cloud providers, Kubernetes, Vault, Docker, PyPI and SSH keys.
⛧ BLACK VEIL // PRIVATE SERVICES ⛧

“Some requests are never made publicly.”

01 — THE FIXER
Coordination of private requests, connections, and sensitive agreements.
$1,000

02 — THE BROKER
Mediation of communication and negotiation between private parties.
$2,500

03 — THE HANDLER
Management of private files and task processes.
$5,000

04 — THE GHOST
Private agent whose identity and background are kept confidential.
$10,000

05 — THE CLEANER
Control of complex situations and crisis management.
$15,000

06 — THE SPYMASTER
Sensitive information, intelligence analysis, and private investigation services.
$25,000

07 — BLACK CONTRACT
Preparation of highly confidential private agreements.
$50,000

08 — OMEGA ACCESS
BLACK VEIL's highest level exclusive service package.
$100,000

---

⛧ PRIVATE CONTACT

SESSION
"050bbbee83794febed3c001a153cf99f2474b71f0952ba019fc62a1b206401a819"

TELEGRAM
"@Cipher5Network"

"PRIVATE CHANNEL" (https://reference-url-citation.invalid/0)

---

"NO PUBLIC LISTING"
"PRIVATE REQUESTS ONLY"
"ACCESS BY APPROVAL"
"BLACK VEIL // 2026"

STATUS: "ACTIVE"
ACCESS: "RESTRICTED"
CLIENTS: "UNKNOWN"

 
5,464Threads
74,682Messages
5,791Members
brainstormy73738iLatest member
Top Bottom