Post B6tqKbB4tcGyyWpA3s by Solarinas@posthat.ca
(DIR) More posts by Solarinas@posthat.ca
(DIR) Post #B6tpkSaRMLztuESGxs by arstechnica@mastodon.social
0 likes, 1 repeats
Dozens of Red Hat packages backdoored through its offical NPM channelAnyone who has downloaded affected Red Hat packages should investigate immediately.https://arstechnica.com/security/2026/06/dozens-of-red-hat-packages-backdoored-through-its-offical-npm-channel/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social
(DIR) Post #B6tqKbB4tcGyyWpA3s by Solarinas@posthat.ca
0 likes, 0 repeats
@arstechnica This is really really badI want to hear Red Hat's response to this. It seems like somehow someone was able to merge code into their repo. I'm very curious on how someone managed to do that, and what protections they have to prevent these kinds of merges. Sounds like they circumvented a review process, or didn't have a review process at all on the repoI'm sure Red Hat will have a full write up on this once they get all the details