HeadlinesBriefing favicon HeadlinesBriefing.com

Red Hat npm packages compromised in security breach

Hacker News •
×

Red Hat confirmed multiple malicious npm releases across its `@redhat-cloud-services/` scope, exposing developers to potential security risks. The compromised packages include critical components like compliance-client, frontend-components, and rbac-client, affecting various Red Hat Cloud Services.

Over 40 npm packages were compromised with specific malicious versions, including 2.3.1 for chrome, 4.0.3 for compliance-client, and 9.0.3 for rbac-client. Red Hat has not yet released official security advisories or patches, leaving developers vulnerable to potential data breaches or unauthorized access through dependency injection.

Developers using Red Hat Cloud Services must immediately audit their dependencies and avoid the listed compromised versions. The incident underscores ongoing challenges in the npm ecosystem's security model, where supply chain attacks continue to target legitimate packages through compromised publishing credentials.