A supply chain worm dubbed Miasma has been found in dozens of @redhat-cloud-services npm releases. The malicious preinstall hook steals credentials, probes cloud identities, and can republish other packages.
Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages
calendar_today
June 1, 2026
domain
snyk