npm supply chain attack Miasma compromised 32 Red Hat packages June 1 via a hijacked CI/CD pipeline producing valid SLSA attestations, then hit 57 more June 3 using Phantom Gyp to evade install monitors. Red Hat confirmed no official products were affected. Developers must immediately rotate all cloud credentials, GitHub tokens, and SSH keys.