MEDIUMSupply Chain
Global

Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages

·Source: Snyk

Updated:

Executive Summary

A supply chain worm dubbed Miasma has been found in dozens of @redhat-cloud-services npm releases. The malicious preinstall hook steals credentials, probes cloud identities, and can republish other packages.

Analysis

A supply chain worm dubbed Miasma has been found in dozens of @redhat-cloud-services npm releases. The malicious preinstall hook steals credentials, probes cloud identities, and can republish other packages.
Source Attribution

Originally published by Snyk on Jun 1, 2026.

Related Threats