On June 1, 2026, Aikido detected that 96 versions across 32 packages in the @redhat-cloud-services npm scope were compromised with malware similar to the Mini Shai-Hulud worm, which was recently open-sourced by TeamPCP and targets cloud credentials and CI/CD pipelines. The compromised packages accumulated approximately 116,991 combined weekly downloads, enabling threat actors to replicate the attack techniques across the Red Hat ecosystem.