ClosedLow impactAI Refreshed

Red Hat npm Packages Compromised in Supply-Chain Credential Attack

Occurred 1 May 2026Β·Detected 1 Jun 2026Β·
πŸ‡ΊπŸ‡Έ Global supply-chain attack via Red Hat npm namespace; Red Hat headquartered in US9 reportsEnded 15 Jun 2026
CyberPolitical Violence & WarPropertyCyberCasualty & Liability

A supply-chain attack compromised more than 30 npm packages in Red Hat's '@redhat-cloud-services' namespace, distributing 'Miasma' credential-stealing malware, a variant of the Shai-Hulud worm. A related and rapidly contained incident saw Microsoft remove 73 GitHub repositories across Azure, microsoft, Azure-Samples, and MicrosoftDocs organisations, with Microsoft reporting containment within 105 seconds and full restoration, exposing a 'small number' of customers. The Miasma/Shai-Hulud toolkit was subsequently published publicly on GitHub, and researchers separately identified IronWorm, a Rust-based npm-targeting infostealer with self-propagation and credential-theft capabilities. No named insured commercial losses, financial loss estimates, claims, or notices of circumstance have been reported.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Low impact. The combined Red Hat npm compromise, Microsoft GitHub repository incident, public release of the Miasma toolkit, and emergence of IronWorm demonstrate escalating, cross-ecosystem reach of credential-stealing worms into hyperscale cloud and developer-tooling environments. However, no concrete London Market loss pathway is evidenced: no named insured commercial entities have confirmed losses, no financial loss estimates have been published, and no claims, reserving, or underwriting actions are referenced. Microsoft's 105-second containment and full repository restoration, combined with only a 'small number' of potentially exposed customers, further limit near-term insured loss exposure. The event remains a watch-list item for cyber underwriters monitoring developer toolchain exposures but does not meet the threshold for MEDIUM without confirmed downstream insured losses.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Geographic Zone Matches

3 active matches

  • TRIA Certified Areas
    Rule-basedConfidence 100%
  • Pacific Ring of Fire
    Rule-basedConfidence 100%
  • Caribbean Hurricane Zone
    Rule-basedConfidence 100%

Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.

Affected countries

πŸ‡¦πŸ‡Ί AustraliaπŸ‡§πŸ‡ͺ BelgiumπŸ‡¨πŸ‡¦ CanadaπŸ‡¨πŸ‡­ SwitzerlandπŸ‡©πŸ‡ͺ GermanyπŸ‡ͺπŸ‡Έ SpainπŸ‡«πŸ‡· FranceπŸ‡¬πŸ‡§ United Kingdom

+4 more

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts