Tag: chaindrop
6 articles

Web3 Enables Sophisticated Cloud Supply Chain Attacks
Malware authors are now using blockchain technology to launch devastating cloud supply chain attacks, as seen in the ChainDrop attack that infected over 400 npm packages. This sneaky tactic uses a custom runtime to launch a credential harvester, allowing attackers to capture sensitive cloud provider IAM keys and more.

Supply Chain Attacks Target SDLC's Overlooked Corners
Meet the ChainDrop npm worm, a sneaky threat that infiltrated over 400 packages, including popular libraries like keyv and cacheable-request, by hiding in plain sight within routine developer workflows. This highly evasive threat uses a three-step chain to steal sensitive tokens and secrets, spreading its reach with alarming ease.

ChainDrop Worm Infiltrates npm Supply Chain, Evades Defenses
A sneaky new worm called ChainDrop has infiltrated the npm supply chain, infecting 444 packages that are downloaded a whopping 2 billion times each month. This stealthy attack uses a clever tactic, targeting package tarballs rather than repository source commits to evade defenses.

ChainDrop Worm Exposes npm Ecosystem Vulnerabilities
A sneaky self-propagating worm called ChainDrop has infected over 400 popular npm packages, putting hundreds of millions of downloads at risk each week and threatening developer workstations, CI runners, and cloud instances. This clever malware hides in plain sight by masquerading as legitimate code, making it a formidable foe in the npm ecosystem.

Worm Compromises 430 npm Packages
A massive credential-stealing campaign, dubbed ChainDrop, has compromised over 430 npm packages, impacting a staggering two billion monthly installs, with security researchers tracing the intrusion back to a single GitHub account hack on August 4. The breach has hit some major players, including cacheable, flat-cache, and file-entry-cache, with tens of millions of downloads each month.

npm Supply-Chain Attack Exposes Hundreds of Packages
A massive npm supply-chain attack has compromised at least 868 packages, with over 1,300 affected and a staggering 2 billion monthly downloads impacted. The self-propagating malware, ChainDrop, has spread rapidly, infecting widely-used caching utilities and leaving a trail of damage in its wake.