- Red Hat npm packages compromised with Mini Shai-Hulud variant
- Attackers target GitHub secrets and cloud credentials
- Copycat worm shows themed but similar tradecraft
Numerous Red Hat npm packages were recently compromised and tainted with a variant of the Mini Shai-Hulu worm, targeting GitHub Actions secrets, npm tokens, and other valuable information. Thousands of developers and projects are potentially at risk.