Tag: credential stealing campaign
1 article

Worm Compromises 430 npm Packages
A massive credential-stealing campaign, dubbed ChainDrop, has compromised over 430 npm packages, impacting a staggering two billion monthly installs, with security researchers tracing the intrusion back to a single GitHub account hack on August 4. The breach has hit some major players, including cacheable, flat-cache, and file-entry-cache, with tens of millions of downloads each month.