ChainDrop Worm Poisons 444 npm Packages, Evades Security Defenses

TL;DR. A new variant of the Shai-Hulud npm worm, dubbed ChainDrop, has infected 444 open-source packages, using novel propagation methods. - ChainDrop bypasses standard open-source repository safeguards by spreading via tarballs and directly modifying repository configuration files. - The malware seeks npm tokens with write privileges and cloud credentials, activating upon opening an infected Git branch in development environments. - The attack targeted widely used infrastructure dependencies downloaded billions of times monthly, posing a significant supply chain threat.

Sources

Back to QLANKR News