216.73.217.22

Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages

· Published 01/06/2026 19:31 · Modified 02/06/2026 09:29

Export JSON

Essential information

Published
01/06/2026 19:31
Modified
02/06/2026 09:29
Tags
2026-06-01 ci/cd targeting npm compromise shai-hulud supply chain attack
Related entities
5 observables, 2 malware, 1 others

Description

A compromised multiple @redhat-cloud-services npm packages, executing malicious payloads automatically during installation via preinstall hooks. The attack uses AES-GCM encrypted payloads and obfuscated JavaScript loaders to harvest GitHub Actions secrets, npm tokens, cloud credentials (AWS, Azure, GCP), Kubernetes and Vault material, SSH keys, Git credentials, and cryptocurrency wallet files. The payload can daemonize on developer workstations, includes Russian-locale avoidance mechanisms, and exfiltrates stolen data through encrypted HTTPS channels with GitHub API fallback mechanisms. The campaign employs tactics similar to the publicly released toolkit, though attribution remains unclear due to the availability of open-source attack tooling.

External references