@redhat-cloud-services publish pipeline is compromised today and shipped a signed, trusted, malicious npm package (opens in new tab)
The attacker compromised the @redhat-cloud-services GitHub Actions OIDC trusted publisher to ship patch-client@4.0.4 with a Mini Shai-Hulud worm. The same publisher controls 32 packages across the scope. The payload harvests cloud, CI, and registry credentials and self-propagates through stolen tokens.
Read the original article