Preinstall to persistence: Inside the npm Miasma credential-stealing campaign

Reported 04 Jun 2026 by otx · Severity: medium

Microsoft Threat Intelligence discovered a large-scale npm supply chain attack compromising 32 malicious packages across over 90 versions under the @redhat-cloud-services scope. The compromise originated from the RedHatInsights/javascript-clients CI/CD pipeline, enabling attacker