Miasma Supply Chain Malware pada paket npm Red Hat Cloud Services
June 2, 2026
Deskripsi
1
| |
|
|
| |
Miasma adalah supply chain attack yang menyusupi paket @redhat-cloud-services di npm untuk mencuri credentials, secrets developer, dan data CI/CD. Kampanye ini diidentifikasi pada 1 Juni 2026, dengan indikasi aktivitas awal muncul pada 29 Mei 2026. (wiz.io) Severity: High
|
|
| |
|
|
Metode Serangan
2
| |
|
|
| |
payload obfuscated dijalankan otomatis melalui preinstall saat npm install, lalu mengumpulkan GitHub/npm/cloud credentials, mengekfiltrasi data terenkripsi, dan dapat menyebar ke repository lain lewat GitHub API serta workflow injection. (socket.dev)
|
|
| |
|
|
Sistem Terdampak
3
| |
|
|
| |
developer workstation, build runner, container build, dan pipeline GitHub Actions/CI/CD yang menginstal paket @redhat-cloud-services; setidaknya 32 release terdampak, termasuk chrome@2.3.1, vulnerabilities-client@2.1.8, dan tsc-transform-imports@1.2.2/1.2.3/1.2.5. (socket.dev)
|
|
| |
|
|
Mitigasi
4
| |
|
|
| |
- Isolasi host/runner yang pernah menginstal versi terdampak dan hentikan sementara workflow CI/CD terkait. (socket.dev)
- Hapus versi berbahaya dari project/lockfile, bersihkan cache package, lalu rebuild dari environment yang bersih. (socket.dev)
- Rotasi GitHub token, npm token, cloud credentials, SSH keys, dan secrets lain yang mungkin terekspos. (socket.dev)
- Audit GitHub dan npm activity untuk branch, workflow, commit, atau artifact mencurigakan setelah 29 Mei 2026. (socket.dev)
|
|
| |
|
|
Referensi: ?
1. https://thecyberexpress.com/miasma-shai-hulud-supply-chain-attack/