Minacce · 52 giorni fa
Il punto non è più la compromissione di un singolo maintainer. ChainDrop ora si autoalimenta: una volta rubati i token npm e GitHub, li riusa per firmare la prossima ondata di release malevole, così la risposta standard basata sulla sola revoca delle credenziali rischia di riattivare la propagazione invece di fermarla.
Le fonti confermano circa 2.200 release malevole su 440 pacchetti, con impatto su keyv, cacheable, flat-cache, file-entry-cache e cache-manager. Il veicolo è un preinstall hook che parte durante l’installazione normale, sottrae segreti e poi usa quegli stessi accessi per pubblicare nuovi pacchetti infetti; in scope ci sono installazioni npm, workspace aperti negli IDE e contesti CI/CD.
Per i team JavaScript che pubblicano o consumano pacchetti npm, il contenimento non coincide più con la pulizia di un repo o con il cambio di token. Se il malware ha già girato su workstation o runner, la catena di fiducia del publishing può restare compromessa e riaccendersi da un’altra copia del codice.
15 fonti che coprono questa storia
ChainDrop: Inside a Self-Propagating npm Worm
Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing.
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages — Elastic Security Labs
Elastic Defend provides coverage for the latest npm supply chain attack.
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, Author: Renato Marinho
ChainDrop: campagna worm auto-propagante nell’ecosistema npm
Ricercatori di sicurezza hanno recentemente identificato una campagna di compromissione della supply chain software presente nell’ecosistema npm - denominata “ChainDrop” - che ha interessato oltre 400 pacchetti appartenenti a maintainer e organizzazioni differenti.
ChainDrop Worm Hits 400 npm Packages with Two Billion Monthly Installs
A new npm worm has compromised packages with over two billion monthly installs
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
ChainDrop supply chain compromise: Anatomy of a self-propagating worm | Microsoft Security Blog
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates.
Massive supply-chain attack compromises 440 packages under four hours
A self-replicating Mini Shai-Hulud worm compromised 860+ npm packages, including keyv, stealing cloud credentials and developer secrets across global environments.
ChainDrop credential stealing worm infects over 400 npm packages
The Shai Hulud variant’s blast radius includes several highly popular packages thus far..
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
A Keyv-linked npm worm poisoned 353 versions across 79 package names, stealing developer and CI credentials while repository hooks remained present.
keyv and cacheable npm Package Hijacked in Supply Chain Attack | Wiz Blog
Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages.
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
Part of the PlainSec briefing for 2026-08-07