
ChainDrop Publishes Initial Malware Without Stealing a Long-Lived npm Token
The ChainDrop campaign has exposed a gap in modern software supply-chain defenses: malware no longer needs a durable npm publishing token or even an npm install event to spread through developer environments. The self-propagating npm worm, also tracked as a Mini Shai-Hulud variant, turned compromised publisher and CI identities into a distribution mechanism while establishing […]
The post ChainDrop Publishes Initial Malware Without Stealing a Long-Lived npm Token appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.