On June 1, 2026, Wiz Research identified a supply chain compromise affecting at least 32 package releases under the @redhat-cloud-services npm namespace, cumulatively averaging ~80,000 weekly downloads.
A specific Red Hat employee GitHub account was compromised and used to inject malware via orphan commits to RedHatInsights repositories across two waves. Workflows triggered on push to any branch with id-token: write permission, executing obfuscated _index.js that published packages with valid SLSA provenance attestations — same pattern as TeamPCP’s TanStack attack.
Complete IOC table lists compromised package versions for topological-inventory-client, compliance-client, rbac-client, insights-client, frontend-components, and 27 additional packages.