COMPAMIR
High-Purity Fact Pipeline
High-Purity Fact Pipeline
Red Hat / TeamPCP (suspected)
Global
June 2, 2026
Verified: June 2, 2026
"Security researchers identified dozens of Red Hat npm packages infected with the Mini Shai-Hulud worm. The attack originated from a compromised Red Hat employee's GitHub account, bypassing code reviews. The malware is designed to steal sensitive credentials, including cloud and Kubernetes secrets."
Author: Mark Dowd, John McDonald, and Justin Schuh
This book provides a deep dive into the mechanics of software vulnerabilities and the methodology of security assessments, which is essential for understanding how supply chain attacks like malicious npm packages bypass code reviews and compromise infrastructure.
As an Amazon Associate, COMPAMIR earns from qualifying purchases.