Impact
The Miasma campaign placed malicious code into npm releases under the @redhat-cloud-services scope. Public research describes install-time execution and credential collection risk for developer workstations and CI runners [S1][S2][S3]. A repository dependency match is exposure evidence; it does not by itself prove that the package was installed, that lifecycle scripts ran, or that secrets were stolen [S3].
Root Cause
The incident was a supply-chain compromise of published npm packages under a trusted vendor namespace. Public reporting links the malicious releases to compromised upstream publishing access and release artifacts that diverged from the corresponding source repositories [S1][S2]. Updated reporting lists additional package versions associated with the Miasma campaign [S1][S3].
Covered by FixVibe
FixVibe's GitHub repo scans flag known compromised @redhat-cloud-services package versions reported in public Miasma research [S1][S3] in package manifests and npm, pnpm and Yarn lockfiles, showing the package, resolved version, source file and dependency path.
Remediation
Remove the affected package version, regenerate the active lockfile from a trusted registry state, rebuild CI images, devcontainers, Docker layers, and deployed artifacts that may have cached the dependency, then rerun the FixVibe GitHub repo scan. If the affected version was installed on a workstation or CI runner, rotate npm tokens, GitHub tokens, cloud credentials, SSH keys, deployment secrets, and other secrets that were reachable during installation. Do not validate cleanup by executing the compromised package or triggering install lifecycle scripts.
