Dozens of Red Hat packages backdoored through its official NPM channel
Summary
Dozens of Red Hat published packages distributed via its official npm channel were found to include a backdoor. Users who pulled the affected versions are urged to investigate for compromise and remove the malicious packages.
Why it matters
Compromised packages in an official npm channel can silently infect thousands of deployments through normal dependency updates.