
ChainDrop npm Worm Hijacks GitHub Actions OIDC to Poison 444 Packages With Valid SLSA Provenance
A new npm supply-chain campaign, tracked as ChainDrop and also called Mini Shai-Hulud, shows how attackers can turn trusted developer tools into a worm delivery system. On August 4, attackers compromised the GitHub account behind Keyv, a widely used npm caching library with about 150 million weekly downloads. Related packages, including cacheable, flat-cache, file-entry-cache, cache-manager, […]
The post ChainDrop npm Worm Hijacks GitHub Actions OIDC to Poison 444 Packages With Valid SLSA Provenance appeared first on Cyber Security News.