Last Updated: 2026-06-02T17:32:42Z
What’s Happening
Yet another “Shai-Hulud” style NPM attack, this time against Red Hat cloud services packages. Socket has the full report.
Affected packages have been unpublished, but it’s unclear if new packages have yet been issued, or the root cause of the compromise identified.
Red Hat has a security bulletin, but with limited information at this time.
Actions
Review the listed packages and versions for compromise. Full package list here:
https://socket.dev/supply-chain-attacks/red-hat-cloud-services-package-compromise
Consider anything in your environment with these packages compromised, as well as any tokens/secrets present on that system.
Review the indicators of compromise, in particular the execution of bun from non-standard locations. This continues to be a high-fidelity indicator of this attack type, and should be highly monitored/alerted, if not outright blocked.
Notes
This appears to be using the playbook demonstrated in the open source “Mini Shai-Hulud” repository released by TeamPCP last month.
The network indicators of compromise are entirely “trusted sites.” It is interesting that primary exfiltration is to Claude via api.anthropic[.]com. It will be interesting to see how they’re using Claude in this way. That said, the URL from Socket is incomplete, and Step Security’s writeup omits that C2 as of now.