Supply Chain Attack
Mini Shai-Hulud 'Miasma' Variant Compromises 32 Red Hat Cloud Services npm Packages
A compromised Red Hat employee GitHub account pushed a new 'Miasma' build of the Mini Shai-Hulud worm into 32 Cloud Services npm packages. Red Hat says the code was internal-only and never reached customers; any pipeline that installed a poisoned version should rotate its secrets.