Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Coach vs mentor – Who can help you level up your career?
    • Flush With Cash From OpenAI, Opal Is Making an AI-Powered Audio Gadget
    • Dozens of Red Hat packages backdoored through its official NPM channel
    • Microsoft Build 2026 Kicks Off Today: Live Updates on Copilot AI and Dev Tools
    • From Regex to Vision Models: Which RAG Technique Fits Which Problem
    • Rehumanizing global health care with agentic AI
    • Robots-Blog | Praxisprojekt mit fischertechnik an der Hochschule Hof in Bayern
    • Ancient giant octopuses were apex predators, study finds
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Tuesday, June 2
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Dozens of Red Hat packages backdoored through its official NPM channel
    News

    Dozens of Red Hat packages backdoored through its official NPM channel

    Editor Times FeaturedBy Editor Times FeaturedJune 2, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    The worm, dubbed Shai-Hulud, has all of the hallmarks of malware released final month as freely obtainable open supply. TeamPCP was the primary group to make use of Shai-Hulud, and it promoted a contest that promised a $1,000 fee to the hacker who carried out the most important supply-chain assault utilizing the malware. TeamPCP has additionally been behind a rash of previous supply-chain attacks. Now that the worm is within the palms of many different menace teams, supply-chain assaults might ramp up additional.

    The malware devotes appreciable consideration to CI/CD (steady integration/steady supply) programs, which permit for sooner and extra dependable software program releases by automating the constructing, testing, and deploying of code adjustments. The malware unfold in Monday’s assault was printed via GitHub Actions OIDC (OpenID Join), indicating that Purple Hat’s CI/CD pipeline was compromised. OIDC is a safety measure designed to work together with cloud companies via the usage of short-term credentials.

    As soon as put in, the malware targets different organizations’ CI/CD credentials. The compromise of Purple Hat’s GitHub Actions OIDC was very presumably the results of a earlier supply-chain assault that contaminated an worker’s machine.

    In an e-mail despatched after this submit went reside, Purple Hat stated it has eliminated the malicious packages.

    “The packages are strictly restricted to inside improvement, and the malicious code was by no means printed for buyer consumption by way of the console.redhat.com system,” the e-mail stated. “Whereas our investigation is ongoing, we’ve got not recognized any influence to buyer or accomplice environments or Purple Hat manufacturing programs.”

    Given the success of different current supply-chain assaults, anybody who touched one of many affected packages previously 36 hours ought to assume compromise of their workstations, CI/CD pipelines, and all credentials for cloud companies and repositories. Meaning staff ought to drop no matter they’re doing in the mean time and examine totally.

    In a recent supply-chain attack that hit Checkmarx, the safety agency failed to completely drive out the get together accountable. Checkmarx was then hit two extra instances. The Checkmarx credentials used within the first assault got here from a provide chain assault on the Trivy software program developer. The pivot to Checkmarx and its failure to completely remediate the preliminary breach demonstrates the issue of utterly recovering from such safety lapses and the dangers that consequence.

    Each Socket and Aikido have lists of affected Purple Hat packages and different indicators of compromise that any probably affected individual or group ought to make use of promptly.

    Story up to date so as to add Purple Hat remark.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    CFTC seeks injunction in Kalshi Rhode Island dispute

    June 2, 2026

    Florida crackdown targets illegal machines in Sarasota

    June 2, 2026

    Hawthorne bankruptcy dispute targets Illinois racing funds

    June 2, 2026

    Kalshi debuts regulated crypto perpetual futures

    June 2, 2026

    Manchester gambling raid sparks wider enforcement focus

    June 2, 2026

    Burbank laboratory owner sentenced over Medicare gambling fraud

    June 1, 2026
    Leave A Reply Cancel Reply

    Editors Picks

    Coach vs mentor – Who can help you level up your career?

    June 2, 2026

    Flush With Cash From OpenAI, Opal Is Making an AI-Powered Audio Gadget

    June 2, 2026

    Dozens of Red Hat packages backdoored through its official NPM channel

    June 2, 2026

    Microsoft Build 2026 Kicks Off Today: Live Updates on Copilot AI and Dev Tools

    June 2, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Dassault unveils VORTEX spaceplane at Paris Air Show

    June 27, 2025

    AI models can develop ‘humanlike’ gambling addiction when given more freedom

    January 3, 2026

    Pumpkin, Fanta or Cheetos: What Flavor of Orange Is the Cosmic Orange iPhone 17 Pro?

    September 20, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.