Package @redhat-cloud-services/[email protected] published June 1, 2026 through GitHub Actions trusted publisher contains a Mini Shai-Hulud worm. A single preinstall hook runs a 4.3 MB index.js that ROT-9 decodes a loader, AES-128-GCM decrypts a 634 KB Bun script, downloads Bun runtime, and executes the payload.
The payload scans AWS, Azure, GCP, HashiCorp Vault, Kubernetes, npm, GitHub, and password manager secrets; exfiltrates to attacker-created public GitHub repositories; republishes into other packages; injects .github/workflows/codeql.yml; and installs AI-agent persistence hooks.
Clean version is 9.0.3. Pin to 9.0.3 or earlier and rotate all reachable credentials immediately.