ChainDrop Worm Poisons 444 npm Packages, Evades Security Defenses
TL;DR. A new variant of the Shai-Hulud npm worm, dubbed ChainDrop, has infected 444 open-source packages, using novel propagation methods. - ChainDrop bypasses standard open-source repository safeguards by spreading via tarballs and directly modifying repository configuration files. - The malware seeks npm tokens with write privileges and cloud credentials, activating upon opening an infected Git branch in development environments. - The attack targeted widely used infrastructure dependencies downloaded billions of times monthly, posing a significant supply chain threat.
- ChainDrop, a Shai-Hulud npm worm variant, infected 444 open-source packages.
- It uses tarballs and direct repository configuration modifications to evade detection.
- The malware extracts npm tokens and cloud credentials, activating upon opening infected Git branches.
- Targeted infrastructure dependencies are downloaded approximately 2 billion times monthly.
Sources
- ChainDrop worm crawls into npm supply chain, evades standard defenses — theregister.com