
ChainDrop npm Worm Poisons 444 Packages Through GitHub Actions and Trusted Publishing
ChainDrop has made an npm package compromise a warning about developer machines. The self-propagating campaign poisoned 444 packages and more than 1,300 malicious releases after attackers took over the GitHub account tied to the Keyv caching library. The affected packages represented more than two billion monthly installs. The operation spread through stolen npm publishing tokens […]
The post ChainDrop npm Worm Poisons 444 Packages Through GitHub Actions and Trusted Publishing appeared first on Cyber Security News.