Miasma Malware Hits 32 Red Hat Packages via Compromised GitHub Account
2026-06-05T20:51:42Z•a2a793b6054c21b28a5e815582fb04b611ce7a36b611aa263503c74d5e000527
Atlas-MenuCI/CD-secretsFive-EyesGitHub-account-compromiseLazarus GroupMiasmaReaperSHubSilentRunLoaderTA4922brandjackingcloud-tokenscredentials-theftdata-breachdeveloper-credentialseSIMfake-job-adsiFoodmacOS-infostealernpmpackage-compromisephishingsupply-chain
What happened
Multiple active incidents and campaigns reported: Miasma malware compromised a compromised GitHub account to inject malicious code into 32 Red Hat npm packages, exposing cloud tokens, CI/CD secrets and developer credentials in a supply‑chain attack. Related npm risks include Lazarus Group brandjacking packages to target developers. macOS users face a new Reaper infostealer (SHub variant) that abuses Script Editor to bypass protections and steal crypto and passwords. Significant data breaches were disclosed: Atlas Menu leak (≈64,000 cheat‑service users) and an iFood breach affecting ~1.2M users
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- a2a793b6054c21b28a5e815582fb04b611ce7a36b611aa263503c74d5e000527
- Enrichment time
- 2026-06-05T20:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.