supply-chain
ChainDrop worm crawls into npm supply chain, evades standard defenses
High
Summary
A ChainDrop worm is exploiting vulnerabilities within the npm package manager supply chain, bypassing standard security defenses. This allows attackers to inject malicious code into legitimate packages, potentially compromising numerous applications and systems that rely on those packages. The worm is actively targeting npm packages, and is a significant threat to software supply chain security.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data