Red Hat's official @redhat-cloud-services npm scope was backdoored today with a worm derived from the open-sourced Mini Shai-Hulud malware. Socket caught it first; Aikido, BleepingComputer, and The Hacker News (which is calling the campaign "Miasma") corroborate within hours.
This is the trusted-vendor shape the npm ecosystem has been bracing for since last summer's original Shai-Hulud: install-time payload, CI/CD secret exfiltration, self-propagation to reachable repositories. The day's other live attack — codexui-android, an npm package marketed as a remote UI for OpenAI Codex — is smaller (29,000+ weekly downloads, still live on npm at writing) but carries the same install-on-trust shape and is exfiltrating Codex auth tokens from every developer who runs it. Underneath the active campaigns, three KEV adds reinforce the registry-trust theme — Nx Console's VS Code extension (CISA flags ransomware use as known), TanStack's npm packages (same flag), and a fresh same-day Oracle WebLogic add with a 72-hour federal deadline. The developer-tooling layer is having a bad week: dual critical Vitest browser-mode CVEs and six concurrent praisonai-platform authorization advisories round out the slate.
→ Operational priority for the night grep every CI build log and developer-workstation install record from the past 72 hours for @redhat-cloud-services, codexui-android, @tanstack/*, and Nx Console; treat any match as a credentials-compromised build, rotate cloud and OpenAI/Codex tokens that touched those environments, and pin lockfiles to clean versions before tomorrow's first build.