Miasma: Supply Chain Compromise in RedHat npm Packages - Credential Harvesting Malware

Miasma: Supply Chain Compromise in RedHat npm Packages (TL-2026-0983), also tracked as npm Miasma, is a critical-severity malware campaign, first published 2026-06-01. It is attributed to TeamPCP with high confidence, affects RedHat / Cloudflare @redhat-cloud-services npm packages, maps to 22 MITRE ATT&CK techniques (T1003, T1005, T1020), and is covered by 9 detection rules and 15 indicators of compromise.

Key facts for TL-2026-0983

Threat ID
TL-2026-0983
Also known as
npm Miasma, TeamPCP npm Supply Chain
Severity
CRITICAL
Status
ACTIVE
Category
MALWARE
First published
2026-06-01
Last reviewed
2026-06-01
Attribution
TeamPCP
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
software-development, cloud-infrastructure, financial-services, technology, government administration, health, telecoms
Target regions
North America, Europe, Asia Pacific, Global (npm ecosystem)
Detection rules
9
Indicators of compromise
15

Malware and tooling in Miasma: Supply Chain Compromise in RedHat npm Packages

Malware and tooling: Miasma, Custom exfiltration endpoint, TeamPCP

TeamPCP deployed Miasma malware across 29+ @redhat-cloud-services npm package versions, using obfuscated preinstall scripts to harvest cloud credentials from GCP and Azure environments. Active exploitation via npm package distribution affecting infrastructure automation and cloud management tooling.

How Miasma: Supply Chain Compromise in RedHat npm Packages works

Miasma represents a sophisticated supply chain compromise targeting the npm ecosystem, specifically the @redhat-cloud-services namespace which provides widely-deployed infrastructure packages. The threat actor TeamPCP compromised package maintainer credentials or leveraged registry account takeover to inject malicious preinstall scripts into multiple package versions. The malware employs obfuscation techniques to evade automated and manual detection during code review. Upon installation, the preinstall hook executes automatically without user interaction, executing Node.js code that enumerates and harvests cloud service credentials from the victim system. Targeted credential sources include environment variables, configuration files in home directories (.aws/credentials, .azure/config, ~/.kube/config, GCP service account JSON files), and cloud SDK credential stores. Harvested credentials are exfiltrated to attacker-controlled infrastructure, enabling unauthorized access to cloud accounts and lateral movement within affected organizations. The 29+ compromised releases span multiple packages over an extended timeframe, indicating sustained access to the package maintenance infrastructure. This attack represents one of the most critical supply chain compromises in the npm ecosystem due to the privileged nature of infrastructure and cloud management packages.

MITRE ATT&CK techniques used in TL-2026-0983

Credential Access

T1003 OS Credential Dumping; T1212 Exploitation for Credential Access; T1528 Steal Application Access Token; T1552 Unsecured Credentials

Collection

T1005 Data from Local System; T1074 Data Staged

Exfiltration

T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

Persistence

T1053 Scheduled Task/Job

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery

credential-access

T1187 Forced Authentication

Initial Access

T1195 Supply Chain Compromise; T1199 Trusted Relationship

Impact

T1486 Data Encrypted for Impact; T1531 Account Access Removal

Affected products and versions in Miasma: Supply Chain Compromise in RedHat npm Packages

  • RedHat / Cloudflare — @redhat-cloud-services npm packages (infrastructure namespace)
    Vulnerable versions: @redhat-cloud-services/*, versions released between 2026-04-15 and 2026-06-01 (29+ releases across multiple packages)
    Fixed in: All versions released after 2026-06-10 (post-incident remediation)
  • Google Cloud Platform — GCP Service Accounts and Credentials
    Vulnerable versions: All credentials potentially exposed from affected systems
  • Microsoft Azure — Azure Service Principals and Credentials
    Vulnerable versions: All credentials potentially exposed from affected systems
  • npm — npm Registry
    Vulnerable versions: All systems using npm versions <9.0 without preinstall script validation

Remediation for Miasma: Supply Chain Compromise in RedHat npm Packages

Patches

  • Use only @redhat-cloud-services package versions released after 2026-06-10 (post-compromise remediation)
  • Verify package signatures and checksums against official RedHat/Cloudflare repositories

Immediate actions

  • Rotate all GCP service account credentials and Azure credentials that may have been present in ~/.azure, ~/.kube, or environment variables
  • Scan audit logs in GCP and Azure for unauthorized access from June 2026 onwards
  • Block npm package installations from @redhat-cloud-services namespace in package-lock and dependency trees
  • Revoke all tokens and credentials stored in npm configurations
  • Isolate and quarantine all systems where @redhat-cloud-services packages were installed

Workarounds

  • Temporarily replace @redhat-cloud-services packages with equivalent alternatives
  • Use npm offline mode with pre-verified package copies
  • Deploy application containers with reduced credential access and assume-role patterns instead of direct credential storage

Longer-term hardening

  • Implement npm package signing verification and checksum validation in CI/CD pipelines
  • Deploy EDR with behavioral detection for Node.js preinstall script execution
  • Establish npm2fa enforcement for all package maintainers
  • Monitor npm registry for unauthorized releases using package integrity verification
  • Implement cloud credential detection in file system scanning (AWS/Azure/GCP credential patterns)
  • Establish baseline for credential file access patterns and alert on anomalies

Weaknesses (CWE) in Miasma: Supply Chain Compromise in RedHat npm Packages

CWE-1104, CWE-1112, CWE-427, CWE-506, CWE-912

Timeline of Miasma: Supply Chain Compromise in RedHat npm Packages

  • Suspected initial compromise of npm package maintainer credentials or registry account takeover by TeamPCP
  • First compromised @redhat-cloud-services package version released to npm registry with Miasma preinstall script
  • Miasma malware actively distributed through npm ecosystem as part of dependency chains for infrastructure and cloud management packages
  • 29+ compromised package releases identified spanning multiple @redhat-cloud-services projects
  • CISA issues alert regarding supply chain compromise in npm ecosystem
  • RedHat and Cloudflare issue security advisories regarding compromised @redhat-cloud-services packages
  • Wiz Threat Report publicly discloses Miasma supply chain compromise and TeamPCP attribution
  • npm and package maintainers reset compromised account credentials and regain control of package namespace
  • Post-incident remediated versions of @redhat-cloud-services packages released without malicious payloads

Sources cited for Miasma: Supply Chain Compromise in RedHat npm Packages

Threats related to Miasma: Supply Chain Compromise in RedHat npm Packages

Detection coverage for TL-2026-0983

As of 2026-06-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0983 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats