Mini Shai-Hulud "Miasma: The Spreading Blight" Hits @redhat-cloud-services: Multiple Packages at Risk On June 1, 2026, an attacker exploited npm's trusted publishing mechanism to compromise 32 @redhat-cloud-services packages across 96 versions, injecting malicious preinstall hooks that execute a Bun-based worm upon npm install. The worm harvests cloud credentials, vault tokens, Kubernetes service account tokens, and other secrets, exfiltrating them to attacker-controlled GitHub repositories while self-propagating through injected CI workflows. The third wave of malicious publishes remains live as the latest versions, meaning any user upgrading to the current patch installs the payload. Mini Shai-Hulud "Miasma: The Spreading Blight" Hits @redhat-cloud-services: Multiple Packages at Risk Table of Contents TL;DR On June 1, 2026, an attacker abused npm’s GitHub Actions trusted publishing to ship malicious versions of 32 @redhat-cloud-services packages, 96 versions in total, every one carrying valid npm provenance. The root cause is in the provenance itself: npm binds trusted publishing to a repository plus a workflow filename, not to a branch. The attacker pushed short-lived oidc-