Utopia Tech
▸ Engineering & Strategy Journal

Field notes from the edge.

What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing WormAI
Security

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

A supply chain attack dubbed Miasma has compromised Red Hat npm packages (@redhat-cloud-services) to deploy credential-stealing malware and a self-propagating worm on developer systems. The campaign employs Mini Shai-Hulud tactics including install-time execution, credential harvesting, CI/CD pipeline targeting, and encrypted data exfiltration. This incident represents a significant threat to ente

UTUtopia Tech·1 min
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain AttackAI
Security

OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack

A malicious supply chain attack targeting developers has been discovered in the codexui-android npm package, which masquerades as a legitimate remote web UI for OpenAI Codex. The compromised package, still available on npm and GitHub, has attracted over 29,000 weekly downloads and is designed to steal OpenAI Codex authentication tokens from unsuspecting developers.

UTUtopia Tech·1 min
Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer SecretsAI
Security

Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets

Cybersecurity researchers have identified malicious code in three versions of the popular npm package node-ipc (versions 9.1.6, 9.2.3, and 12.0.1), which contains stealer backdoor functionality targeting developer credentials and secrets. The compromised package poses significant supply chain security risks to enterprise development environments that rely on Node.js dependencies.

UTUtopia Tech·1 min
Skip to main content