{"id":181856,"date":"2026-06-02T08:48:05","date_gmt":"2026-06-02T06:48:05","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat"},"modified":"2026-06-02T08:48:05","modified_gmt":"2026-06-02T06:48:05","slug":"atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","title":{"rendered":"Gli aggressori hanno integrato malware in 32 pacchetti NPM di Red Hat","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>A seguito della compromissione del processo di creazione delle versioni basato su GitHub Actions nei repository di RedHatInsights, di propriet\u00e0 di Red Hat, gli attaccanti sono riusciti a pubblicare nel catalogo NPM 64 versioni malevole che coprono 32 pacchetti NPM per la piattaforma Red Hat Cloud Services. Per ogni pacchetto NPM compromesso sono state rilasciate due versioni malevole, che integravano codice per attivare una nuova variante del worm mini-shai-hulud, in grado di cercare token e credenziali nell'ambiente attuale. <\/p>\n<p>Il worm era presente nel file index.js e si attivava tramite un gestore preinstallazione, chiamato durante l'installazione del pacchetto compromesso. Dopo l'attivazione, il worm cercava nel sistema token per NPM (~\/.npmrc), PyPI, CircleCI, AWS, GCP, Docker, Azure, HashiCorp e KubernetesK8s, oltre a chiavi SSH chiuse. I dati trovati venivano inviati agli aggressori. In caso di rilevamento di un token per la connessione al catalogo NPM, il worm pubblicava automaticamente nuove versioni malevole per i pacchetti in fase di sviluppo nell'ambiente attuale, colpendo l'albero delle dipendenze.  <\/p>\n<p>L'accesso a GitHub Actions \u00e8 stato ottenuto a seguito della compromissione dell'account di un dipendente di Red Hat, permettendo agli attaccanti di inviare direttamente commit nei repository javascript-clients, frontend-components e platform-frontend-ai-toolkit, senza passare per la fase di revisione. Attraverso i commit, il file ci.yaml \u00e8 stato inserito nel sistema di integrazione continua, il quale, all'avvio del processo di costruzione, eseguiva tramite la piattaforma bun lo script _index.js. Lo script utilizzava il permesso \u00abid-token: write\u00bb per richiedere a GitHub un token OIDC (OpenID Connect), che veniva poi utilizzato per l'autenticazione in NPM tramite il meccanismo \u00abtrusted publishing\u00bb.<\/p>\n<p>Pacchetti NPM contenenti codice malevolo:<\/p>\n<ul>\n<li>@redhat-cloud-services\/chrome (2.3.1, 2.3.2)<\/li>\n<li>@redhat-cloud-services\/compliance-client (4.0.3, 4.0.4)<\/li>\n<li>@redhat-cloud-services\/config-manager-client (5.0.4, 5.0.5)<\/li>\n<li>@redhat-cloud-services\/entitlements-client (4.0.11, 4.0.12)<\/li>\n<li>@redhat-cloud-services\/eslint-config-redhat-cloud-services (3.2.1, 3.2.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components (7.7.2, 7.7.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-advisor-components (3.8.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components-config (6.11.3, 6.11.4)<\/li>\n<li>@redhat-cloud-services\/frontend-components-config-utilities (4.11.2, 4.11.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-notifications (6.9.2, 6.9.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-remediations (4.9.2, 4.9.3)<\/li>\n<li>@redhat-cloud-services\/frontend-components-testing (1.2.1, 1.2.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components-translations (4.4.1, 4.4.2)<\/li>\n<li>@redhat-cloud-services\/frontend-components-utilities (7.4.1, 7.4.2)<\/li>\n<li>@redhat-cloud-services\/hcc-feo-mcp (0.3.1, 0.3.2)<\/li>\n<li>@redhat-cloud-services\/hcc-kessel-mcp (0.3.1, 0.3.2)<\/li>\n<li>@redhat-cloud-services\/hcc-pf-mcp (0.6.1, 0.6.2)<\/li>\n<li>@redhat-cloud-services\/host-inventory-client (5.0.3, 5.0.4)<\/li>\n<li>@redhat-cloud-services\/insights-client (4.0.4, 4.0.5)<\/li>\n<li>@redhat-cloud-services\/integrations-client (6.0.4, 6.0.5)<\/li>\n<li>@redhat-cloud-services\/javascript-clients-shared (2.0.8, 2.0.9)<\/li>\n<li>@redhat-cloud-services\/notifications-client (6.1.4, 6.1.5)<\/li>\n<li>@redhat-cloud-services\/patch-client (4.0.4, 4.0.5)<\/li>\n<li>@redhat-cloud-services\/quickstarts-client (4.0.11, 4.0.12)<\/li>\n<li>@redhat-cloud-services\/rbac-client (9.0.3, 9.0.4)<\/li>\n<li>@redhat-cloud-services\/remediations-client (4.0.4, 4.0.5)<\/li>\n<li>@redhat-cloud-services\/rule-components (4.7.2, 4.7.3)<\/li>\n<li>@redhat-cloud-services\/sources-client (3.0.10, 3.0.11)<\/li>\n<li>@redhat-cloud-services\/topological-inventory-client (3.0.10, 3.0.11)<\/li>\n<li>@redhat-cloud-services\/tsc-transform-imports (1.2.2)<\/li>\n<li>@redhat-cloud-services\/types (3.6.1, 3.6.2, 3.6.4)<\/li>\n<li>@redhat-cloud-services\/vulnerabilities-client (2.1.8, 2.1.9)\n<\/ul>\n<p>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=65599\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438, \u043e\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0435 32 NPM-\u043f\u0430\u043a\u0435\u0442\u0430 \u0434\u043b\u044f \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Red Hat Cloud Services. \u0414\u043b\u044f \u043a\u0430\u0436\u0434\u043e\u0433\u043e \u0438\u0437 \u043f\u043e\u0440\u0430\u0436\u0451\u043d\u043d\u044b\u0445 NPM-\u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0431\u044b\u043b\u0438 \u0432\u044b\u043f\u0443\u0449\u0435\u043d\u044b \u043f\u043e \u0434\u0432\u0435 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0431\u044b\u043b \u0438\u043d\u0442\u0435\u0433\u0440\u0438\u0440\u043e\u0432\u0430\u043d \u043a\u043e\u0434 \u0434\u043b\u044f \u0430\u043a\u0442\u0438\u0432\u0430\u0446\u0438\u0438 \u043d\u043e\u0432\u043e\u0433\u043e \u0432\u0430\u0440\u0438\u0430\u043d\u0442\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-181856","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0410\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0435 \u0432\u0441\u0442\u0440\u043e\u0438\u043b\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0432 32 NPM-\u043f\u0430\u043a\u0435\u0442\u0430 Red Hat | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-06-02T06:48:05+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-06-02T06:48:05+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Gli aggressori hanno incorporato malware in 32 pacchetti NPM di Red Hat | ProHoster","description":"A seguito di una compromissione del processo di creazione delle release tramite GitHub Actions nei repository RedHatInsights di propriet\u00e0 della Red Hat, gli aggressori sono riusciti a pubblicare 64 versioni dannose nel catalogo NPM.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0410\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0435 \u0432\u0441\u0442\u0440\u043e\u0438\u043b\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0432 32 NPM-\u043f\u0430\u043a\u0435\u0442\u0430 Red Hat | ProHoster","og:description":"\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0435\u043b\u0438\u0437\u043e\u0432 \u043d\u0430 \u0431\u0430\u0437\u0435 GitHub Actions \u0432 \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Red Hat \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 RedHatInsights, \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0441\u043c\u043e\u0433\u043b\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 NPM 64 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0432\u0435\u0440\u0441\u0438\u0438.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/atakuyushhie-vstroili-vredonosnoe-po-v-32-npm-paketa-red-hat","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-06-02T06:48:05+00:00","article:modified_time":"2026-06-02T06:48:05+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/181856","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=181856"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/181856\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=181856"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=181856"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=181856"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}