{"id":181856,"date":"2026-06-02T08:48:05","date_gmt":"2026-06-02T06:48:05","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat"},"modified":"2026-06-02T08:48:05","modified_gmt":"2026-06-02T06:48:05","slug":"atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","title":{"rendered":"Des attaquants ont int\u00e9gr\u00e9 des logiciels malveillants dans 32 paquets NPM de Red Hat.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00c0 la suite de la compromission du processus de cr\u00e9ation de versions bas\u00e9 sur GitHub Actions dans les d\u00e9p\u00f4ts RedHatInsights appartenant \u00e0 Red Hat, des attaquants ont r\u00e9ussi \u00e0 publier 64 versions malveillantes dans le r\u00e9pertoire NPM, couvrant 32 paquets NPM pour la plateforme Red Hat Cloud Services. Pour chaque paquet NPM affect\u00e9, deux versions malveillantes ont \u00e9t\u00e9 publi\u00e9es, int\u00e9grant du code pour activer une nouvelle variante du ver mini-shai-hulud, effectuant la recherche de jetons et de donn\u00e9es d'identification dans l'environnement actuel. <\/p>\n<p>Le ver \u00e9tait contenu dans le fichier index.js et s'activait via un gestionnaire preinstall, d\u00e9clench\u00e9 lors de l'installation du paquet affect\u00e9. Une fois activ\u00e9, le ver recherchait dans le syst\u00e8me des jetons pour NPM (~\/.npmrc), PyPI, CircleCI, AWS, GCP, Docker, Azure, HashiCorp et KubernetesK8s, ainsi que des cl\u00e9s SSH priv\u00e9es. Les donn\u00e9es trouv\u00e9es \u00e9taient envoy\u00e9es aux attaquants. En cas de d\u00e9tection d'un jeton de connexion au r\u00e9pertoire NPM, le ver publiait automatiquement de nouvelles versions malveillantes pour les paquets en d\u00e9veloppement dans l'environnement actuel, touchant l'arbre des d\u00e9pendances.  <\/p>\n<p>L'acc\u00e8s aux GitHub Actions a \u00e9t\u00e9 obtenu \u00e0 la suite de la compromission du compte d'un employ\u00e9 de Red Hat, permettant aux attaquants d'envoyer directement des commits dans les d\u00e9p\u00f4ts javascript-clients, frontend-components et platform-frontend-ai-toolkit, sans passer par la phase de r\u00e9vision. \u00c0 travers ces commits, un fichier ci.yaml \u00e9tait ins\u00e9r\u00e9 dans le syst\u00e8me d'int\u00e9gration continue, qui, lors du lancement du travail de compilation, ex\u00e9cutait le script _index.js \u00e0 l'aide de la plateforme bun. Ce script utilisait le droit \u00ab id-token: write \u00bb pour demander \u00e0 GitHub un jeton OIDC (OpenID Connect), qui \u00e9tait ensuite utilis\u00e9 pour l'authentification dans NPM via le m\u00e9canisme de \u00ab trusted publishing \u00bb.<\/p>\n<p>Paquets NPM contenant du code malveillant :<\/p>\n<ul>\n<li>@redhat-cloud-services\/chrome (2.3.1, 2.3.2)<\/li>\n<li>@redhat-cloud-services\/compliance-client (4.0.3, 4.0.4)<\/li>\n<li>@redhat-cloud-services\/config-manager-client (5.0.4, 5.0.5)<\/li>\n<li>@redhat-cloud-services\/entitlements-client (4.0.11, 4.0.12)<\/li>\n<li>@redhat-cloud-services\/eslint-config-redhat-cloud-services (3.2.1, 3.2.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components (7.7.2, 7.7.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-advisor-components (3.8.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components-config (6.11.3, 6.11.4)<\/li>\n<li>@redhat-cloud-services\/frontend-components-config-utilities (4.11.2, 4.11.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-notifications (6.9.2, 6.9.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-remediations (4.9.2, 4.9.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-testing (1.2.1, 1.2.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components-translations (4.4.1, 4.4.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components-utilities (7.4.1, 7.4.2)<\/li>\n<li>@redhat-cloud-services\/hcc-feo-mcp (0.3.1, 0.3.2)<\/li>\n<li>@redhat-cloud-services\/hcc-kessel-mcp (0.3.1, 0.3.2)<\/li>\n<li>@redhat-cloud-services\/hcc-pf-mcp (0.6.1, 0.6.2)<\/li>\n<li>@redhat-cloud-services\/host-inventory-client (5.0.3, 5.0.4)<\/li>\n<li>@redhat-cloud-services\/insights-client (4.0.4, 4.0.5)<\/li>\n<li>@redhat-cloud-services\/integrations-client (6.0.4, 6.0.5)<\/li>\n<li>@redhat-cloud-services\/javascript-clients-shared (2.0.8, 2.0.9)<\/li>\n<li>@redhat-cloud-services\/notifications-client (6.1.4, 6.1.5)<\/li>\n<li>@redhat-cloud-services\/patch-client (4.0.4, 4.0.5)<\/li>\n<li>@redhat-cloud-services\/quickstarts-client (4.0.11, 4.0.12)<\/li>\n<li>@redhat-cloud-services\/rbac-client (9.0.3, 9.0.4)<\/li>\n<li>@redhat-cloud-services\/remediations-client (4.0.4, 4.0.5)<\/li>\n<li>@redhat-cloud-services\/rule-components (4.7.2, 4.7.3)<\/li>\n<li>@redhat-cloud-services\/sources-client (3.0.10, 3.0.11)<\/li>\n<li>@redhat-cloud-services\/topological-inventory-client (3.0.10, 3.0.11)<\/li>\n<li>@redhat-cloud-services\/tsc-transform-imports (1.2.2)<\/li>\n<li>@redhat-cloud-services\/types (3.6.1, 3.6.2, 3.6.4)<\/li>\n<li>@redhat-cloud-services\/vulnerabilities-client (2.1.8, 2.1.9)\n<\/ul>\n<p>Source : <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=65599\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438, \u043e\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0435 32 NPM-\u043f\u0430\u043a\u0435\u0442\u0430 \u0434\u043b\u044f \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Red Hat Cloud Services. \u0414\u043b\u044f \u043a\u0430\u0436\u0434\u043e\u0433\u043e \u0438\u0437 \u043f\u043e\u0440\u0430\u0436\u0451\u043d\u043d\u044b\u0445 NPM-\u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0431\u044b\u043b\u0438 \u0432\u044b\u043f\u0443\u0449\u0435\u043d\u044b \u043f\u043e \u0434\u0432\u0435 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0431\u044b\u043b \u0438\u043d\u0442\u0435\u0433\u0440\u0438\u0440\u043e\u0432\u0430\u043d \u043a\u043e\u0434 \u0434\u043b\u044f \u0430\u043a\u0442\u0438\u0432\u0430\u0446\u0438\u0438 \u043d\u043e\u0432\u043e\u0433\u043e \u0432\u0430\u0440\u0438\u0430\u043d\u0442\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-181856","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0410\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0435 \u0432\u0441\u0442\u0440\u043e\u0438\u043b\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0432 32 NPM-\u043f\u0430\u043a\u0435\u0442\u0430 Red Hat | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-06-02T06:48:05+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-06-02T06:48:05+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Des attaquants ont int\u00e9gr\u00e9 des logiciels malveillants dans 32 paquets NPM de Red Hat | ProHoster","description":"\u00c0 la suite d'une compromission du processus de cr\u00e9ation des versions sur GitHub Actions dans les d\u00e9p\u00f4ts RedHatInsights appartenant \u00e0 Red Hat, des attaquants ont pu publier 64 versions malveillantes dans le r\u00e9pertoire NPM.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0410\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0435 \u0432\u0441\u0442\u0440\u043e\u0438\u043b\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0432 32 NPM-\u043f\u0430\u043a\u0435\u0442\u0430 Red Hat | ProHoster","og:description":"\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-06-02T06:48:05+00:00","article:modified_time":"2026-06-02T06:48:05+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/181856","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=181856"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/181856\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=181856"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=181856"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=181856"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}