On June 1, 2026, security researchers discovered that 32 packages in the @redhat-cloud-services npm namespace were compromised with a credential-stealing worm called Miasma. The attack exploited a hijacked Red Hat employee’s GitHub account to inject malicious code into official packages, bypassing code review processes. The malware leveraged trusted CI/CD pipelines to distribute itself and steal credentials from infected systems.