{"id":181856,"date":"2026-06-02T08:48:05","date_gmt":"2026-06-02T06:48:05","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat"},"modified":"2026-06-02T08:48:05","modified_gmt":"2026-06-02T06:48:05","slug":"atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","title":{"rendered":"Gli attaccanti hanno integrato malware in 32 pacchetti NPM di Red Hat.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>A seguito della compromissione del processo di creazione delle release basate su GitHub Actions nei repository RedHatInsights di propriet\u00e0 di Red Hat, i malintenzionati sono riusciti a pubblicare 64 versioni dannose nel catalogo NPM, che colpiscono 32 pacchetti NPM per la piattaforma Red Hat Cloud Services. Per ogni pacchetto NPM compromesso sono state rilasciate due versioni dannose, integrate con codice per attivare una nuova variante del worm mini-shai-hulud, che esegue la ricerca di token e credenziali nell'ambiente corrente. <\/p>\n<p>Il worm era contenuto nel file index.js e si attivava tramite un gestore preinstallazione, invocato durante l'installazione del pacchetto compromesso. Dopo l'attivazione, il worm cercava nella sistema token NPM (~\/.npmrc), PyPI, CircleCI, AWS, GCP, Docker, Azure, HashiCorp e KubernetesK8s, oltre a chiavi SSH private. I dati trovati venivano inviati ai malintenzionati. In caso di scoperta di un token per accedere al catalogo NPM, il worm pubblicava automaticamente nuove release dannose per i pacchetti in fase di sviluppo nell'ambiente corrente, colpendo l'albero delle dipendenze.  <\/p>\n<p>L'accesso a GitHub Actions \u00e8 stato ottenuto a seguito della compromissione dell'account di uno dei dipendenti di Red Hat, consentendo agli attaccanti di inviare direttamente commit nei repository javascript-clients, frontend-components e platform-frontend-ai-toolkit, senza passare attraverso la fase di revisione. Tramite i commit nel sistema di integrazione continua, veniva iniettato un file ci.yaml che, al momento dell'avvio del lavoro di build, eseguiva tramite la piattaforma bun lo script _index.js. Lo script utilizzava il diritto \"id-token: write\" per richiedere a GitHub un token OIDC (OpenID Connect), che veniva poi utilizzato per l'autenticazione su NPM tramite il meccanismo \"trusted publishing\".<\/p>\n<p>Pacchetti NPM contenenti codice dannoso:<\/p>\n<ul>\n<li>@redhat-cloud-services\/chrome (2.3.1, 2.3.2)<\/li>\n<li>@redhat-cloud-services\/compliance-client (4.0.3, 4.0.4)<\/li>\n<li>@redhat-cloud-services\/config-manager-client (5.0.4, 5.0.5)<\/li>\n<li>@redhat-cloud-services\/entitlements-client (4.0.11, 4.0.12)<\/li>\n<li>@redhat-cloud-services\/eslint-config-redhat-cloud-services (3.2.1, 3.2.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components (7.7.2, 7.7.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-advisor-components (3.8.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components-config (6.11.3, 6.11.4)<\/li>\n<li>@redhat-cloud-services\/frontend-components-config-utilities (4.11.2, 4.11.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-notifications (6.9.2, 6.9.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-remediations (4.9.2, 4.9.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-testing (1.2.1, 1.2.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components-translations (4.4.1, 4.4.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components-utilities (7.4.1, 7.4.2)<\/li>\n<li>@redhat-cloud-services\/hcc-feo-mcp (0.3.1, 0.3.2)<\/li>\n<li>@redhat-cloud-services\/hcc-kessel-mcp (0.3.1, 0.3.2)<\/li>\n<li>@redhat-cloud-services\/hcc-pf-mcp (0.6.1, 0.6.2)<\/li>\n<li>@redhat-cloud-services\/host-inventory-client (5.0.3, 5.0.4)<\/li>\n<li>@redhat-cloud-services\/insights-client (4.0.4, 4.0.5)<\/li>\n<li>@redhat-cloud-services\/integrations-client (6.0.4, 6.0.5)<\/li>\n<li>@redhat-cloud-services\/javascript-clients-shared (2.0.8, 2.0.9)<\/li>\n<li>@redhat-cloud-services\/notifications-client (6.1.4, 6.1.5)<\/li>\n<li>@redhat-cloud-services\/patch-client (4.0.4, 4.0.5)<\/li>\n<li>@redhat-cloud-services\/quickstarts-client (4.0.11, 4.0.12)<\/li>\n<li>@redhat-cloud-services\/rbac-client (9.0.3, 9.0.4)<\/li>\n<li>@redhat-cloud-services\/remediations-client (4.0.4, 4.0.5)<\/li>\n<li>@redhat-cloud-services\/rule-components (4.7.2, 4.7.3)<\/li>\n<li>@redhat-cloud-services\/sources-client (3.0.10, 3.0.11)<\/li>\n<li>@redhat-cloud-services\/topological-inventory-client (3.0.10, 3.0.11)<\/li>\n<li>@redhat-cloud-services\/tsc-transform-imports (1.2.2)<\/li>\n<li>@redhat-cloud-services\/types (3.6.1, 3.6.2, 3.6.4)<\/li>\n<li>@redhat-cloud-services\/vulnerabilities-client (2.1.8, 2.1.9)\n<\/ul>\n<p>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=65599\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438, \u043e\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0435 32 NPM-\u043f\u0430\u043a\u0435\u0442\u0430 \u0434\u043b\u044f \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Red Hat Cloud Services. \u0414\u043b\u044f \u043a\u0430\u0436\u0434\u043e\u0433\u043e \u0438\u0437 \u043f\u043e\u0440\u0430\u0436\u0451\u043d\u043d\u044b\u0445 NPM-\u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0431\u044b\u043b\u0438 \u0432\u044b\u043f\u0443\u0449\u0435\u043d\u044b \u043f\u043e \u0434\u0432\u0435 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0431\u044b\u043b \u0438\u043d\u0442\u0435\u0433\u0440\u0438\u0440\u043e\u0432\u0430\u043d \u043a\u043e\u0434 \u0434\u043b\u044f \u0430\u043a\u0442\u0438\u0432\u0430\u0446\u0438\u0438 \u043d\u043e\u0432\u043e\u0433\u043e \u0432\u0430\u0440\u0438\u0430\u043d\u0442\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-181856","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0410\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0435 \u0432\u0441\u0442\u0440\u043e\u0438\u043b\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0432 32 NPM-\u043f\u0430\u043a\u0435\u0442\u0430 Red Hat | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-06-02T06:48:05+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-06-02T06:48:05+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Gli aggressori hanno integrato software dannoso in 32 pacchetti NPM di Red Hat | ProHoster","description":"A causa della compromissione del processo di creazione delle versioni basato su GitHub Actions nei repository RedHatInsights di propriet\u00e0 di Red Hat, gli aggressori sono riusciti a pubblicare 64 versioni dannose nel catalogo NPM.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0410\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0435 \u0432\u0441\u0442\u0440\u043e\u0438\u043b\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0432 32 NPM-\u043f\u0430\u043a\u0435\u0442\u0430 Red Hat | ProHoster","og:description":"\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-06-02T06:48:05+00:00","article:modified_time":"2026-06-02T06:48:05+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/181856","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=181856"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/181856\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=181856"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=181856"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=181856"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}