news.mlab.sh
Back to the feed
supply-chain

Red Hat removes tainted packages after software pipeline compromise

High
Summary

Red Hat removed numerous software packages from its distribution pipeline after a compromised GitHub account was used to distribute credential-stealing malware. The attack, utilizing a variant of the Mini Shai-Hulud worm, impacted over 117,000 weekly downloads and highlights a concerning trend of supply chain attacks targeting developer tools. This incident underscores the vulnerability of software supply chains and the potential for widespread disruption.

The incident began with a compromised GitHub account used to push malicious code to Red Hat customers. The malware, dubbed Miasma, is a variant of the Mini Shai-Hulud worm, originally published by the TeamPCP group. Researchers believe the attackers were incentivized by a BreachForums contest offering $1,000 for the largest supply chain attack utilizing the code. This attack follows a series of similar supply chain intrusions, including recent compromises targeting LiteLLM and the axios JavaScript library, demonstrating a sustained and evolving threat landscape. The potential for cascading effects, as warned by experts like Charles Carmakal, suggests further attacks and associated consequences are likely.

Read the full article at The Record