
ChainDrop Worm Infects 400+ npm Packages to Steal GitHub and Cloud Credentials
ChainDrop has turned routine software installs into a route for credential theft. The self-propagating worm infected more than 400 npm packages, putting developer laptops, build systems and cloud environments at risk. Since compromised packages still work as expected, teams may not realize an update has opened a path into their environment. The campaign spreads through […]
The post ChainDrop Worm Infects 400+ npm Packages to Steal GitHub and Cloud Credentials appeared first on Cyber Security News.