news.mlab.sh
Back to the feed
supply-chain

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

High
Summary

A sophisticated supply chain attack, dubbed ChainDrop, has infected over 2,200 malicious versions of 440 NPM packages, resulting in over 500 million weekly downloads. The attack began with a compromised GitHub account and involved a malware stealer that exfiltrates credentials to various services, including NPM, GitHub, AWS, and HashiCorp Vault. The malware uses a blockchain for command and control and includes a host-level dead-man’s switch to ensure persistence and self-deletion.

Read the full article at SecurityWeek

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.