Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

2026-06-01T19:24:08Z2c25edaa85afc36c61d4931694824c7be815d46bcf72316ec326d7cf8c16afd2
CI/CD-targetingGlassWormLLM-agentMarimoOpenAI-CodexPAN-OSRCEactive-exploitationbotnet-takedowncredential-harvestingcredential-theftdeveloper-supply-chainnpmnugetphishingsupply-chain-attackwordPressworm

What happened

Recent The Hacker News reports describe a surge of high-risk supply‑chain and active‑exploitation activity targeting developer and enterprise environments. Key incidents include the Miasma campaign (a Mini Shai‑Hulud style supply‑chain compromise of @redhat‑cloud‑services npm packages delivering a credential‑stealing, self‑propagating worm), malicious npm/NuGet packages stealing OpenAI Codex tokens, Claude user files, and banking credentials, plus the GlassWorm disruption of developer-targeted infrastructure. Several critical vulnerabilities are actively exploited in the wild (notably PAN‑OS/​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
2c25edaa85afc36c61d4931694824c7be815d46bcf72316ec326d7cf8c16afd2
Enrichment time
2026-06-01T19:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.