
ChainDrop Turns Stolen npm Tokens Into an Automated Package-Infection Engine
A newly identified npm supply-chain worm called ChainDrop is turning stolen developer credentials into an automated package-infection system. The malware has reportedly compromised more than 400 npm packages, including widely used projects such as keyv and cacheable-request, exposing developers, CI/CD pipelines, cloud environments, and downstream users. Unlike a typical malicious package that only steals data […]
The post ChainDrop Turns Stolen npm Tokens Into an Automated Package-Infection Engine appeared first on Cyber Security News.