A sophisticated supply chain attack targeted Red Hat Cloud Services npm packages, executing malware during installation through a preinstall hook that uses encrypted payloads and multiple obfuscation layers to harvest developer credentials, CI/CD secrets, and cloud tokens. Organizations that installed affected versions are advised to treat impacted systems as potentially compromised and immediately rotate exposed credentials.