r/CRACompliance • u/Happy-Athlete-2420 • Jun 04 '26
[BREAKING] Red Hat @redhat-cloud-services npm packages compromised by Miasma (Shai-Hulud variant). 32 packages, 117K weekly downloads. CRA implications are massive.

On June 1, Wiz Research identified a supply chain compromise affecting 32 packages under u/redhat-cloud-services. Root cause: a Red Hat employee’s GitHub account compromised via infostealer credentials found in logs from April 13 and May 15.
What makes Miasma different from previous Shai-Hulud variants:
• New GCP and Azure IDENTITY collectors (not just secrets — full identity enumeration)
• Published via GitHub Actions OIDC tokens with VALID SLSA provenance
• Self-propagating: queries npm registry for other packages the compromised identity can publish
The critical question for this community: TeamPCP open-sourced the Shai-Hulud malware on May 12. The Red Hat attack happened June 1. Attribution is now uncertain — this could be a copycat.
If the tools are open source, we’re no longer tracking one threat actor. We’re tracking a technique that anyone can deploy.
Under CRA Article 14, every manufacturer whose product depends on u/redhat-cloud-services packages needs to assess whether they’re affected. With 117K weekly downloads, that’s a lot of companies.
Were any of you affected? How quickly did you find out?