Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

2026-06-02T01:24:12Z243ae88e7627f4783d7cc27b5444d0a6f2ce5d5fbecd0dbf18537eee9e436bbd
AI-powered-attacksCI/CD-targetingCVE-2026-0257CVE-2026-39987ChatGPhishEKZ-InfostealerFortiClient-EMSGREYVIBEGlassWormGogs-RCEKimsukyMarimoMiasmaOpenAI-tokensPAN-OSWP-Maps-Proactive-exploitationcodexui-androidcredential-theftencrypted-exfiltrationnpmnugetphishingsupply-chainworm

What happened

A cluster of high-impact incidents and campaigns was reported: a new supply-chain campaign dubbed Miasma has compromised @redhat-cloud-services npm packages to deliver a credential‑stealing, self‑propagating worm and target developer machines/CI; multiple other malicious packages (npm, NuGet) are exfiltrating secrets and AI tokens (e.g., codexui-android); and GlassWorm infrastructure was disrupted in a takedown. Several actively exploited vulnerabilities and attacks were highlighted, including PAN-OS GlobalProtect auth bypass (CVE-2026-0257) and Marimo exploitation (CVE-2026-39987) used to exf

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
243ae88e7627f4783d7cc27b5444d0a6f2ce5d5fbecd0dbf18537eee9e436bbd
Enrichment time
2026-06-02T01:24:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm · Baitaphish