Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Build a digital twin agent (with guardrails)
    • Robotiq Launches IQ to Make Palletizing Automation Faster and More Predictable
    • Leica Cine Compact 1: Premium 4K smart projector
    • Coach vs mentor – Who can help you level up your career?
    • Flush With Cash From OpenAI, Opal Is Making an AI-Powered Audio Gadget
    • Dozens of Red Hat packages backdoored through its official NPM channel
    • Microsoft Build 2026 Kicks Off Today: Live Updates on Copilot AI and Dev Tools
    • From Regex to Vision Models: Which RAG Technique Fits Which Problem
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Tuesday, June 2
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Dozens of Red Hat packages backdoored through its official NPM channel
    News

    Dozens of Red Hat packages backdoored through its official NPM channel

    Editor Times FeaturedBy Editor Times FeaturedJune 2, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    The worm, dubbed Shai-Hulud, has all of the hallmarks of malware released final month as freely obtainable open supply. TeamPCP was the primary group to make use of Shai-Hulud, and it promoted a contest that promised a $1,000 fee to the hacker who carried out the most important supply-chain assault utilizing the malware. TeamPCP has additionally been behind a rash of previous supply-chain attacks. Now that the worm is within the palms of many different menace teams, supply-chain assaults might ramp up additional.

    The malware devotes appreciable consideration to CI/CD (steady integration/steady supply) programs, which permit for sooner and extra dependable software program releases by automating the constructing, testing, and deploying of code adjustments. The malware unfold in Monday’s assault was printed via GitHub Actions OIDC (OpenID Join), indicating that Purple Hat’s CI/CD pipeline was compromised. OIDC is a safety measure designed to work together with cloud companies via the usage of short-term credentials.

    As soon as put in, the malware targets different organizations’ CI/CD credentials. The compromise of Purple Hat’s GitHub Actions OIDC was very presumably the results of a earlier supply-chain assault that contaminated an worker’s machine.

    In an e-mail despatched after this submit went reside, Purple Hat stated it has eliminated the malicious packages.

    “The packages are strictly restricted to inside improvement, and the malicious code was by no means printed for buyer consumption by way of the console.redhat.com system,” the e-mail stated. “Whereas our investigation is ongoing, we’ve got not recognized any influence to buyer or accomplice environments or Purple Hat manufacturing programs.”

    Given the success of different current supply-chain assaults, anybody who touched one of many affected packages previously 36 hours ought to assume compromise of their workstations, CI/CD pipelines, and all credentials for cloud companies and repositories. Meaning staff ought to drop no matter they’re doing in the mean time and examine totally.

    In a recent supply-chain attack that hit Checkmarx, the safety agency failed to completely drive out the get together accountable. Checkmarx was then hit two extra instances. The Checkmarx credentials used within the first assault got here from a provide chain assault on the Trivy software program developer. The pivot to Checkmarx and its failure to completely remediate the preliminary breach demonstrates the issue of utterly recovering from such safety lapses and the dangers that consequence.

    Each Socket and Aikido have lists of affected Purple Hat packages and different indicators of compromise that any probably affected individual or group ought to make use of promptly.

    Story up to date so as to add Purple Hat remark.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    CFTC seeks injunction in Kalshi Rhode Island dispute

    June 2, 2026

    Florida crackdown targets illegal machines in Sarasota

    June 2, 2026

    Hawthorne bankruptcy dispute targets Illinois racing funds

    June 2, 2026

    Kalshi debuts regulated crypto perpetual futures

    June 2, 2026

    Manchester gambling raid sparks wider enforcement focus

    June 2, 2026

    Burbank laboratory owner sentenced over Medicare gambling fraud

    June 1, 2026
    Leave A Reply Cancel Reply

    Editors Picks

    Build a digital twin agent (with guardrails)

    June 2, 2026

    Robotiq Launches IQ to Make Palletizing Automation Faster and More Predictable

    June 2, 2026

    Leica Cine Compact 1: Premium 4K smart projector

    June 2, 2026

    Coach vs mentor – Who can help you level up your career?

    June 2, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Why Apple is stuck in tariff tussle

    April 19, 2025

    The AI Hype Index: College students are hooked on ChatGPT

    May 28, 2025

    Best Latex Mattress Options for Natural Support (2025)

    October 12, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.