SlowMist has issued a security alert regarding an active npm supply chain attack targeting software packages related to @redhat-cloud-services. According to ChainCatcher, over 31 packages have been affected, with a weekly download volume of approximately 116,000. More than 300 GitHub repositories have been found with stolen credentials. The attack resembles the previous 'Shai-Hulud' npm attack, involving credential theft, creation of malicious repositories, and automated secret leaks. New suspicious repositories continue to emerge, indicating the attack is ongoing and developers are still being infected.
Potential risks include the theft of GitHub/npm tokens, exposure of AWS/GCP/Azure cloud credentials, collection of SSH keys and Kubernetes secrets, leakage of local environment and wallet data, creation of malicious repositories, and persistent operations. Even after token revocation, destructive actions may occur. It is advised to immediately remove or downgrade affected @redhat-cloud-services package versions, thoroughly audit CI/CD workflows and dependency installations, rotate all GitHub, npm, cloud service, SSH, and wallet-related keys, retain logs, and rebuild exposed developer machines or runners from clean images while maintaining high vigilance.