Skip to main content

Tag: npm package compromise

1 article

Cluttered coding workspace with laptop, manuals, and coffee cups, hinting at network infrastructure.

Worm Compromises 430 npm Packages

A massive credential-stealing campaign, dubbed ChainDrop, has compromised over 430 npm packages, impacting a staggering two billion monthly installs, with security researchers tracing the intrusion back to a single GitHub account hack on August 4. The breach has hit some major players, including cacheable, flat-cache, and file-entry-cache, with tens of millions of downloads each month.

Analyst 207