news.mlab.sh
Back to the feed
threat-intel

ChainDrop: Inside a Self-Propagating npm Worm

High
Image: Palo Alto Unit 42
Summary

A self-propagating npm worm, nicknamed ChainDrop, has infected over 400 packages, collectively downloaded hundreds of millions of times weekly. Developed by a threat actor, the worm steals sensitive data including cloud credentials, npm and GitHub tokens, SSH keys, and AI-tool configurations. It achieves this by leveraging legitimate tools like VS Code and GitHub Actions to establish persistence and exfiltrate data through various channels, including typosquatted repositories and GitHub Actions artifacts. The attackers use a silent propagation method to avoid detection, only activating when specific environment variables are set. Unit 42 has identified and removed the malicious packages and continues to offer assistance to organizations impacted by the attack.

Read the full article at Palo Alto Unit 42

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.