Massive ChainDrop npm supply-chain attack infects hundreds of packages

Massive ChainDrop npm supply-chain attack infects hundreds of packages
ChainDrop is a self-propagating malware campaign that has compromised more than 1,300 npm packages with about 2 billion monthly downloads, including widely used libraries like Keyv, Cacheable, flat-cache, and file-entry-cache. The attack spread through a maintainer’s GitHub account compromise and used legitimate GitHub Actions releases to deliver infostealing payloads targeting developer, cloud, and CI/CD credentials. #ChainDrop #Keyv #Cacheable #Deliveroo #Ornikar #OneReach #Picsart #Qlik #ServiceTitan

Keypoints

  • ChainDrop infected at least 868 packages across 1,381 versions in the npm registry.
  • The attack began after the GitHub account of Keyv’s maintainer was compromised.
  • Malicious releases were published through legitimate GitHub Actions workflows with valid provenance.
  • The payload used setup.mjs to download Bun and run Math_Symbol.js or math_init.js for data theft.
  • The malware stole tokens, secrets, cloud credentials, and other sensitive data from developer systems and CI/CD runners.

Read More: https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/