Dozens of Red Hat packages backdoored through its official NPM channel

Official Red Hat NPM accounts were compromised to distribute malicious packages containing a worm designed to steal sensitive credentials. Security researchers warn that the attack, which began on Monday, targets developers by exploiting trusted software channels.
Why it matters
Supply-chain attacks on widely used software repositories pose a severe risk to enterprise security and cloud infrastructure.
THE RASH OF SUPPLY-CHAIN ATTACKS CONTINUE Dozens of Red Hat packages backdoored through its official NPM channel Anyone who has downloaded affected Red Hat packages should investigate immediately.
Technical reporting on a cybersecurity incident based on researcher findings.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in