INTEL_REPORT
Snyk Blog — AppSec & supply chain · published 6/1/2026, 12:00:00 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages A supply chain worm dubbed Miasma has been found in dozens of @redhat-cloud-services npm releases. The malicious preinstall hook steals credentials, probes cloud identities, and can republish other packages. Miasma Attack Hits Red Hat npm Packages | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a si…
https://snyk.io/blog/miasma-supply-chain-attack-malicious-code-redhat-cloud-services-npm-packages
sha256:22594bd7a808be71b93caa75fc7c4d2703b22049bad5032c85f382b9e5995678
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| plus.probely.app |
| Open → |
| domain | tasks.json | Open → |
| domain | yarn.lock | Open → |
| domain | pnpm-lock.yaml | Open → |
| domain | api.npmjs.org | Open → |
| url | https://api.npmjs.org/downloads/point/last-week/@redhat-cloud-services%2Ftypes | Open → |
| url | https://api.npmjs.org/downloads/point/last-week/@redhat-cloud-services%2Ftypes" | Open → |