:

MALWARE IN NPM PACKAGES TARGETS CLOUD CREDENTIALS

DEV DESK2 MIN READ
MON, JUN 1, 2026

■ AI-SUMMARIZED FROM 4 SOURCES ▸ TIMELINE

Researchers discovered malicious packages in the @redhat-cloud-services npm namespace that harvest credentials for GitHub Actions, AWS, GCP, Azure, and other cloud platforms. The malware executes via preinstall hooks during npm installation.

Security researchers at Step Security identified several packages within the @redhat-cloud-services npm scope containing malicious payloads designed to steal credentials from major cloud platforms and development tools. The attack exploits npm's preinstall hook mechanism, which runs automatically when developers install packages. This approach allows the malware to execute before users notice suspicious activity, making detection difficult. Targeted credentials include authentication tokens for: - GitHub Actions - Amazon Web Services (AWS) - Google Cloud Platform (GCP) - Microsoft Azure - Additional cloud and development platforms The @redhat-cloud-services namespace suggests the packages were designed to appear legitimate to developers working with Red Hat services. This typosquatting-adjacent technique leverages trust associated with established organizations to increase installation rates. Once installed, the preinstall hook fires on every npm install command, potentially compromising credentials across multiple machines and development environments. Stolen credentials could grant attackers access to cloud infrastructure, CI/CD pipelines, and sensitive project resources. The discovery highlights ongoing supply chain vulnerabilities in the npm ecosystem. Developers installing packages from compromised namespaces face significant risk, particularly when packages request broad permissions or execute code during installation phases. Step Security recommends developers: - Audit recent npm installations - Review cloud platform access logs for suspicious activity - Rotate credentials if exposed - Implement package verification tools - Monitor preinstall hook execution Npm has not yet published an official advisory at time of reporting. The incident underscores the importance of scrutinizing package sources and implementing security checks in dependency management workflows.

■ SOURCES

TechmemeTechmemeTechmemeTechmeme

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Threat actors are exploiting ChatGPT and Claude's content-sharing features to distribute malware through fake outage pages and installation guides. The attacks leverage trusted domains to bypass security detection.

JUST NOWAI Desk

Authorities have dismantled a botnet comprising more than 17 million compromised devices. The network was linked to a Russia-based residential proxy operation.

3H AGOIndustry Desk

A class action lawsuit filed in Seattle alleges that Amazon's Ring Familiar Faces feature captures and stores facial data from passersby without their consent. The suit claims the facial recognition tool violates privacy rights.

YESTERDAYIndustry Desk

Russia's Federal Security Service announced it discovered a large-scale spyware operation targeting senior government officials' mobile phones, allegedly orchestrated by foreign intelligence agencies.

JUN 2AI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.