💻
ChainDrop worm poisons 1,300+ npm packages, stealing developer credentials
💻 Technology

ChainDrop worm poisons 1,300+ npm packages, stealing developer credentials

Security researchers at Aikido discovered ChainDrop, a variant of the Shai-Hulud worm, infecting over 1,300 versions of npm packages including popular libraries Keyv and Cacheable with a combined 2 billion monthly downloads. Attackers compromised GitHub accounts of the libraries' maintainers and injected infostealer code targeting developer credentials, API keys and access tokens. Stolen data was exfiltrated to a public GitHub repository; admins of affected systems should treat them as fully compromised.

Comments

No comments yet