How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm

calendar_today June 1, 2026 person domain aikido-security

On June 1, 2026, Aikido detected that 96 versions across 32 packages in the @redhat-cloud-services npm scope were compromised with malware similar to the Mini Shai-Hulud worm, which was recently open-sourced by TeamPCP and targets cloud credentials and CI/CD pipelines. The compromised packages accumulated approximately 116,991 combined weekly downloads, enabling threat actors to replicate the attack techniques across the Red Hat ecosystem.

open_in_new Read original post