Skip to main content

Tag: chaindrop

6 articles

Cluttered developer workstation with laptop, papers, and empty coffee cups, symbolizing a supply chain attack in a cloud…

Web3 Enables Sophisticated Cloud Supply Chain Attacks

Malware authors are now using blockchain technology to launch devastating cloud supply chain attacks, as seen in the ChainDrop attack that infected over 400 npm packages. This sneaky tactic uses a custom runtime to launch a credential harvester, allowing attackers to capture sensitive cloud provider IAM keys and more.

Analyst 207
Cluttered developer workstation with laptop, notes, and empty cans amidst computer hardware and dusty books.

Supply Chain Attacks Target SDLC's Overlooked Corners

Meet the ChainDrop npm worm, a sneaky threat that infiltrated over 400 packages, including popular libraries like keyv and cacheable-request, by hiding in plain sight within routine developer workflows. This highly evasive threat uses a three-step chain to steal sensitive tokens and secrets, spreading its reach with alarming ease.

Analyst 207
Software development workspace with laptop, papers, and coffee cups, surrounded by technical books and equipment.

ChainDrop Worm Infiltrates npm Supply Chain, Evades Defenses

A sneaky new worm called ChainDrop has infiltrated the npm supply chain, infecting 444 packages that are downloaded a whopping 2 billion times each month. This stealthy attack uses a clever tactic, targeting package tarballs rather than repository source commits to evade defenses.

Analyst 207
ChainDrop Worm Exposes npm Ecosystem Vulnerabilities

ChainDrop Worm Exposes npm Ecosystem Vulnerabilities

A sneaky self-propagating worm called ChainDrop has infected over 400 popular npm packages, putting hundreds of millions of downloads at risk each week and threatening developer workstations, CI runners, and cloud instances. This clever malware hides in plain sight by masquerading as legitimate code, making it a formidable foe in the npm ecosystem.

Analyst 207
Cluttered coding workspace with laptop, manuals, and coffee cups, hinting at network infrastructure.

Worm Compromises 430 npm Packages

A massive credential-stealing campaign, dubbed ChainDrop, has compromised over 430 npm packages, impacting a staggering two billion monthly installs, with security researchers tracing the intrusion back to a single GitHub account hack on August 4. The breach has hit some major players, including cacheable, flat-cache, and file-entry-cache, with tens of millions of downloads each month.

Analyst 207
Rows of computer racks and cables in a brightly-lit Java software development environment.

npm Supply-Chain Attack Exposes Hundreds of Packages

A massive npm supply-chain attack has compromised at least 868 packages, with over 1,300 affected and a staggering 2 billion monthly downloads impacted. The self-propagating malware, ChainDrop, has spread rapidly, infecting widely-used caching utilities and leaving a trail of damage in its wake.

Analyst 207