RHSB-2026-006 Supply chain compromise of @redhat-cloud-services npm packages
Updated
Was this information helpful?
Feedback cancelled
Executive Summary
We have completed our investigation into the compromise that we disclosed on June 1, 2026. Our findings identified that on May 29, 2026, a GitHub account, compromised via a VS code extension containing malware, was used to inject malicious code into packages maintained in a Red Hat GitHub organization and altered configuration files to infect other developers opening those directories. The compromised VS code extension was contained on June 1, 2026.
The packages were published under the @redhat-cloud-services npm namespace. The affected packages are frontend JavaScript libraries used in the Hybrid Cloud Console (console.redhat.com) web interface. No release of the Hybrid Cloud Console was published during the compromise window, and Red Hat's publication process includes protections that strip installation-time scripts from packages before deployment to console.redhat.com. These packages are not part of any released Red Hat product, and there is no expectation that a customer would download these packages directly for their own use, as they are built specifically for Console development.
Despite the apparent naming overlap of redhat-cloud-services, the affected packages are not used by any Red Hat-managed cloud services. The following managed services have been verified as not impacted: Azure Red Hat OpenShift (ARO), OpenShift Dedicated (OSD), or Red Hat OpenShift Service on AWS (ROSA), Red Hat Advanced Cluster Security Cloud Service (ACS Cloud Service), or Red Hat Ansible Automation Platform on Cloud (AAP Managed).
Upon learning of the compromise, Red Hat promptly launched an investigation, revoked compromised user and automation tokens, removed the malicious registry packages, corrected the push protection infrastructure, and initiated forensic endpoint isolation.
Technical Summary
The analysis indicated that a compromised GitHub account was used to push unauthorized commits to repositories in the RedHatInsights GitHub organization. Our investigation identified 32 @redhat-cloud-services npm packages that were compromised and published to the npm registry. No additional compromised packages were identified. Red Hat engineering removed compromised versions from npm following disclosure.
No Red Hat products or enterprise software were identified as built or shipped with a compromised version of these packages. Build system and dependency tracking analysis confirmed that no product builds contained compromised package versions. The attack utilized an open-source malware kit known as "Miasma" (also referred to as "Mini Shai-Hulud").
No actions from customers are required. Red Hat closed the incident on 17 June 2026.
Comments