{"id":181856,"date":"2026-06-02T08:48:05","date_gmt":"2026-06-02T06:48:05","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat"},"modified":"2026-06-02T08:48:05","modified_gmt":"2026-06-02T06:48:05","slug":"atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","title":{"rendered":"Attackers Embedded Malware in 32 Red Hat NPM Packages","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>As a result of the compromise of the GitHub Actions release process in repositories owned by Red Hat, attackers were able to publish 64 malicious versions in the NPM directory, covering 32 NPM packages for the Red Hat Cloud Services platform. Two malicious versions were released for each affected NPM package, integrating code to activate a new variant of the mini-shai-hulud worm, which searches for tokens and credentials in the current environment. <\/p>\n<p>The worm was located in the index.js file and was activated via a preinstall handler triggered during the installation of the affected package. After activation, the worm searched the system for tokens for NPM (~\/.npmrc), PyPI, CircleCI, AWS, GCP, Docker, Azure, HashiCorp, and Kubernetes K8s, as well as private SSH keys. The discovered data was sent to the attackers. If a token for connecting to the NPM directory was found, the worm automatically published new malicious releases for the packages being developed in the current environment, affecting the dependency tree.  <\/p>\n<p>Access to GitHub Actions was obtained due to the compromise of an employee's account at Red Hat, which allowed attackers to directly send commits to the javascript-clients, frontend-components, and platform-frontend-ai-toolkit repositories without going through the review stage. Through commits in the continuous integration system, a ci.yaml file was injected, which, when the build job was triggered, executed the _index.js script using the bun platform. The script utilized the 'id-token: write' permission to request an OIDC (OpenID Connect) token from GitHub, which was then used for authentication in NPM through the 'trusted publishing' mechanism.<\/p>\n<p>NPM packages containing malicious code:<\/p>\n<ul>\n<li>@redhat-cloud-services\/chrome (2.3.1, 2.3.2)<\/li>\n<li>@redhat-cloud-services\/compliance-client (4.0.3, 4.0.4)<\/li>\n<li>@redhat-cloud-services\/config-manager-client (5.0.4, 5.0.5)<\/li>\n<li>@redhat-cloud-services\/entitlements-client (4.0.11, 4.0.12)<\/li>\n<li>@redhat-cloud-services\/eslint-config-redhat-cloud-services (3.2.1, 3.2.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components (7.7.2, 7.7.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-advisor-components (3.8.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components-config (6.11.3, 6.11.4)<\/li>\n<li>@redhat-cloud-services\/frontend-components-config-utilities (4.11.2, 4.11.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-notifications (6.9.2, 6.9.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-remediations (4.9.2, 4.9.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-testing (1.2.1, 1.2.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components-translations (4.4.1, 4.4.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components-utilities (7.4.1, 7.4.2)<\/li>\n<li>@redhat-cloud-services\/hcc-feo-mcp (0.3.1, 0.3.2)<\/li>\n<li>@redhat-cloud-services\/hcc-kessel-mcp (0.3.1, 0.3.2)<\/li>\n<li>@redhat-cloud-services\/hcc-pf-mcp (0.6.1, 0.6.2)<\/li>\n<li>@redhat-cloud-services\/host-inventory-client (5.0.3, 5.0.4)<\/li>\n<li>@redhat-cloud-services\/insights-client (4.0.4, 4.0.5)<\/li>\n<li>@redhat-cloud-services\/integrations-client (6.0.4, 6.0.5)<\/li>\n<li>@redhat-cloud-services\/javascript-clients-shared (2.0.8, 2.0.9)<\/li>\n<li>@redhat-cloud-services\/notifications-client (6.1.4, 6.1.5)<\/li>\n<li>@redhat-cloud-services\/patch-client (4.0.4, 4.0.5)<\/li>\n<li>@redhat-cloud-services\/quickstarts-client (4.0.11, 4.0.12)<\/li>\n<li>@redhat-cloud-services\/rbac-client (9.0.3, 9.0.4)<\/li>\n<li>@redhat-cloud-services\/remediations-client (4.0.4, 4.0.5)<\/li>\n<li>@redhat-cloud-services\/rule-components (4.7.2, 4.7.3)<\/li>\n<li>@redhat-cloud-services\/sources-client (3.0.10, 3.0.11)<\/li>\n<li>@redhat-cloud-services\/topological-inventory-client (3.0.10, 3.0.11)<\/li>\n<li>@redhat-cloud-services\/tsc-transform-imports (1.2.2)<\/li>\n<li>@redhat-cloud-services\/types (3.6.1, 3.6.2, 3.6.4)<\/li>\n<li>@redhat-cloud-services\/vulnerabilities-client (2.1.8, 2.1.9)\n<\/ul>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=65599\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438, \u043e\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0435 32 NPM-\u043f\u0430\u043a\u0435\u0442\u0430 \u0434\u043b\u044f \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Red Hat Cloud Services. \u0414\u043b\u044f \u043a\u0430\u0436\u0434\u043e\u0433\u043e \u0438\u0437 \u043f\u043e\u0440\u0430\u0436\u0451\u043d\u043d\u044b\u0445 NPM-\u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0431\u044b\u043b\u0438 \u0432\u044b\u043f\u0443\u0449\u0435\u043d\u044b \u043f\u043e \u0434\u0432\u0435 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0431\u044b\u043b \u0438\u043d\u0442\u0435\u0433\u0440\u0438\u0440\u043e\u0432\u0430\u043d \u043a\u043e\u0434 \u0434\u043b\u044f \u0430\u043a\u0442\u0438\u0432\u0430\u0446\u0438\u0438 \u043d\u043e\u0432\u043e\u0433\u043e \u0432\u0430\u0440\u0438\u0430\u043d\u0442\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-181856","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0410\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0435 \u0432\u0441\u0442\u0440\u043e\u0438\u043b\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0432 32 NPM-\u043f\u0430\u043a\u0435\u0442\u0430 Red Hat | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-06-02T06:48:05+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-06-02T06:48:05+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Attackers embedded malware into 32 Red Hat NPM packages | ProHoster","description":"As a result of a GitHub Actions release process compromise in the Red Hat repositories owned by Red Hat, attackers were able to publish 64 malicious versions in the NPM registry.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0410\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0435 \u0432\u0441\u0442\u0440\u043e\u0438\u043b\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0432 32 NPM-\u043f\u0430\u043a\u0435\u0442\u0430 Red Hat | ProHoster","og:description":"\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-06-02T06:48:05+00:00","article:modified_time":"2026-06-02T06:48:05+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/181856","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=181856"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/181856\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=181856"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=181856"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=181856"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}