ctipilot.ch

Miasma worm backdoors 32 @redhat-cloud-services npm packages (TeamPCP / Mini Shai-Hulud variant)

campaign · campaign:miasma-redhat-npm-supply-chain

Coverage timeline
1
first 2026-06-02 → last 2026-06-02
Briefs
1
1 distinct
Sources cited
4
4 hosts
Sections touched
1
active_threats
Co-occurring entities
2
see Related entities below

Story timeline

  1. 2026-06-02CTI Daily Brief — 2026-06-02
    active_threatsFirst coverage. TeamPCP-attributed OIDC trusted-publishing abuse; new Miasma variant adds GCP/Azure cloud-identity collectors. Lineage: Mini Shai-Hulud / Shai-Hulud.

Where this entity is cited

  • active_threats1

Source distribution

  • aikido.dev1 (25%)
  • bleepingcomputer.com1 (25%)
  • socket.dev1 (25%)
  • wiz.io1 (25%)

Related entities

Items in briefs about Miasma worm backdoors 32 @redhat-cloud-services npm packages (TeamPCP / Mini Shai-Hulud variant) (1)

"Miasma" worm backdoors 32 Red Hat Cloud Services npm packages via OIDC trusted-publishing abuse

From CTI Daily Brief — 2026-06-02 · published 2026-06-02 · view item permalink →

Threat actor cluster TeamPCP used a compromised Red Hat maintainer GitHub account to inject malicious CI/CD workflows into 32 packages in the @redhat-cloud-services npm namespace, poisoning 96 releases across high-traffic packages — Wiz puts the combined weekly downloads at roughly 80,000, while Aikido counts closer to 117,000 (Wiz, 2026-06-01 · Aikido Security, 2026-06-01). Rather than compromising developer machines directly, the attack abused GitHub Actions OIDC trusted publishing so the CI/CD pipeline itself republished backdoored packages carrying obfuscated preinstall hooks. The "Miasma" payload — a new variant in the Mini Shai-Hulud / Shai-Hulud lineage — sweeps for GitHub Actions secrets, npm tokens, AWS keys, SSH keys, HashiCorp Vault and Kubernetes credentials, and now adds dedicated collectors for GCP service-account and Azure managed-identity tokens, signalling a pivot from developer-host theft toward cloud-account takeover (Socket, 2026-06-01). Wiz notes the new variant's cloud-identity focus explicitly.

Why it matters to us: Red Hat tooling has a broad EU public-sector DevOps footprint (OpenShift/OpenStack estates). Inventory installed @redhat-cloud-services/* versions across build agents and developer endpoints, alert on preinstall scripts spawning obfuscated node -e chains from npm/npx parent trees, and rotate any CI/CD cloud-identity tokens reachable from affected pipelines.