Miasma Malware Hits 32 Red Hat Packages via Compromised GitHub Account

2026-06-05T20:51:42Za2a793b6054c21b28a5e815582fb04b611ce7a36b611aa263503c74d5e000527
Atlas-MenuCI/CD-secretsFive-EyesGitHub-account-compromiseLazarus GroupMiasmaReaperSHubSilentRunLoaderTA4922brandjackingcloud-tokenscredentials-theftdata-breachdeveloper-credentialseSIMfake-job-adsiFoodmacOS-infostealernpmpackage-compromisephishingsupply-chain

What happened

Multiple active incidents and campaigns reported: Miasma malware compromised a compromised GitHub account to inject malicious code into 32 Red Hat npm packages, exposing cloud tokens, CI/CD secrets and developer credentials in a supply‑chain attack. Related npm risks include Lazarus Group brandjacking packages to target developers. macOS users face a new Reaper infostealer (SHub variant) that abuses Script Editor to bypass protections and steal crypto and passwords. Significant data breaches were disclosed: Atlas Menu leak (≈64,000 cheat‑service users) and an iFood breach affecting ~1.2M users

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
a2a793b6054c21b28a5e815582fb04b611ce7a36b611aa263503c74d5e000527
Enrichment time
2026-06-05T20:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.