{"id":181856,"date":"2026-06-02T08:48:05","date_gmt":"2026-06-02T06:48:05","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat"},"modified":"2026-06-02T08:48:05","modified_gmt":"2026-06-02T06:48:05","slug":"atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","title":{"rendered":"Los atacantes introdujeron malware en 32 paquetes NPM de Red Hat","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Como resultado de la compromisi\u00f3n del proceso de generaci\u00f3n de lanzamientos basado en GitHub Actions en los repositorios de RedHatInsights de la empresa Red Hat, los atacantes pudieron publicar 64 versiones maliciosas en el cat\u00e1logo de NPM, abarcando 32 paquetes de NPM para la plataforma Red Hat Cloud Services. Para cada uno de los paquetes de NPM afectados, se emitieron dos versiones maliciosas que integraban c\u00f3digo para activar una nueva variante del gusano mini-shai-hulud, que busca tokens y credenciales en el entorno actual. <\/p>\n<p>El gusano se alojaba en el archivo index.js y se activaba a trav\u00e9s de un manejador preinstall que se invocaba durante la instalaci\u00f3n del paquete afectado. Tras su activaci\u00f3n, el gusano buscaba en el sistema tokens de NPM (~\/.npmrc), PyPI, CircleCI, AWS, GCP, Docker, Azure, HashiCorp y KubernetesK8s, as\u00ed como claves SSH privadas. Los datos encontrados se enviaban a los atacantes. En caso de descubrir un token de conexi\u00f3n al cat\u00e1logo de NPM, el gusano publicaba autom\u00e1ticamente nuevas versiones maliciosas para los paquetes en desarrollo en el entorno actual, afectando el \u00e1rbol de dependencias.  <\/p>\n<p>El acceso a GitHub Actions se obtuvo como resultado de la compromisi\u00f3n de la cuenta de uno de los empleados de Red Hat, lo que permiti\u00f3 a los atacantes enviar directamente commits a los repositorios javascript-clients, frontend-components y platform-frontend-ai-toolkit, sin pasar por la etapa de revisi\u00f3n. A trav\u00e9s de los commits en el sistema de integraci\u00f3n continua, se introdujo un archivo ci.yaml que, al ejecutar el trabajo de construcci\u00f3n, activaba un script _index.js utilizando la plataforma bun. El script utiliz\u00f3 el permiso \"id-token: write\" para solicitar a GitHub un token OIDC (OpenID Connect), que se aplic\u00f3 para la autenticaci\u00f3n en NPM mediante el mecanismo de \"publicaci\u00f3n confiable\".<\/p>\n<p>Los paquetes de NPM que contienen c\u00f3digo malicioso:<\/p>\n<ul>\n<li>@redhat-cloud-services\/chrome (2.3.1, 2.3.2)<\/li>\n<li>@redhat-cloud-services\/compliance-client (4.0.3, 4.0.4)<\/li>\n<li>@redhat-cloud-services\/config-manager-client (5.0.4, 5.0.5)<\/li>\n<li>@redhat-cloud-services\/entitlements-client (4.0.11, 4.0.12)<\/li>\n<li>@redhat-cloud-services\/eslint-config-redhat-cloud-services (3.2.1, 3.2.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components (7.7.2, 7.7.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-advisor-components (3.8.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components-config (6.11.3, 6.11.4)<\/li>\n<li>@redhat-cloud-services\/frontend-components-config-utilities (4.11.2, 4.11.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-notifications (6.9.2, 6.9.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-remediations (4.9.2, 4.9.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-testing (1.2.1, 1.2.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components-translations (4.4.1, 4.4.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components-utilities (7.4.1, 7.4.2)<\/li>\n<li>@redhat-cloud-services\/hcc-feo-mcp (0.3.1, 0.3.2)<\/li>\n<li>@redhat-cloud-services\/hcc-kessel-mcp (0.3.1, 0.3.2)<\/li>\n<li>@redhat-cloud-services\/hcc-pf-mcp (0.6.1, 0.6.2)<\/li>\n<li>@redhat-cloud-services\/host-inventory-client (5.0.3, 5.0.4)<\/li>\n<li>@redhat-cloud-services\/insights-client (4.0.4, 4.0.5)<\/li>\n<li>@redhat-cloud-services\/integrations-client (6.0.4, 6.0.5)<\/li>\n<li>@redhat-cloud-services\/javascript-clients-shared (2.0.8, 2.0.9)<\/li>\n<li>@redhat-cloud-services\/notifications-client (6.1.4, 6.1.5)<\/li>\n<li>@redhat-cloud-services\/patch-client (4.0.4, 4.0.5)<\/li>\n<li>@redhat-cloud-services\/quickstarts-client (4.0.11, 4.0.12)<\/li>\n<li>@redhat-cloud-services\/rbac-client (9.0.3, 9.0.4)<\/li>\n<li>@redhat-cloud-services\/remediations-client (4.0.4, 4.0.5)<\/li>\n<li>@redhat-cloud-services\/rule-components (4.7.2, 4.7.3)<\/li>\n<li>@redhat-cloud-services\/sources-client (3.0.10, 3.0.11)<\/li>\n<li>@redhat-cloud-services\/topological-inventory-client (3.0.10, 3.0.11)<\/li>\n<li>@redhat-cloud-services\/tsc-transform-imports (1.2.2)<\/li>\n<li>@redhat-cloud-services\/types (3.6.1, 3.6.2, 3.6.4)<\/li>\n<li>@redhat-cloud-services\/vulnerabilities-client (2.1.8, 2.1.9)\n<\/ul>\n<p>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=65599\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438, \u043e\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0435 32 NPM-\u043f\u0430\u043a\u0435\u0442\u0430 \u0434\u043b\u044f \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Red Hat Cloud Services. \u0414\u043b\u044f \u043a\u0430\u0436\u0434\u043e\u0433\u043e \u0438\u0437 \u043f\u043e\u0440\u0430\u0436\u0451\u043d\u043d\u044b\u0445 NPM-\u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0431\u044b\u043b\u0438 \u0432\u044b\u043f\u0443\u0449\u0435\u043d\u044b \u043f\u043e \u0434\u0432\u0435 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0431\u044b\u043b \u0438\u043d\u0442\u0435\u0433\u0440\u0438\u0440\u043e\u0432\u0430\u043d \u043a\u043e\u0434 \u0434\u043b\u044f \u0430\u043a\u0442\u0438\u0432\u0430\u0446\u0438\u0438 \u043d\u043e\u0432\u043e\u0433\u043e \u0432\u0430\u0440\u0438\u0430\u043d\u0442\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-181856","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0410\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0435 \u0432\u0441\u0442\u0440\u043e\u0438\u043b\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0432 32 NPM-\u043f\u0430\u043a\u0435\u0442\u0430 Red Hat | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-06-02T06:48:05+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-06-02T06:48:05+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Los atacantes integraron malware en 32 paquetes NPM de Red Hat | ProHoster","description":"Como resultado de la comprometici\u00f3n del proceso de generaci\u00f3n de lanzamientos basado en GitHub Actions en los repositorios RedHatInsights pertenecientes a Red Hat, los atacantes pudieron publicar 64 versiones maliciosas en el cat\u00e1logo de NPM.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0410\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0435 \u0432\u0441\u0442\u0440\u043e\u0438\u043b\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0432 32 NPM-\u043f\u0430\u043a\u0435\u0442\u0430 Red Hat | ProHoster","og:description":"\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-06-02T06:48:05+00:00","article:modified_time":"2026-06-02T06:48:05+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/181856","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=181856"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/181856\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=181856"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=181856"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=181856"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}