A fresh Mini Shai-Hulud supply chain attack, dubbed ChainDrop, poisoned more than 2,200 malicious versions of 440 NPM packages and triggered 433 additional package infections. The worm steals developer and CI/CD secrets, spreads through GitHub and NPM credentials, and uses Ethereum-based EtherHiding plus attacker-controlled GitHub repositories for command and control. #ChainDrop #MiniShaiHulud #ShaiHulud #NPM #GitHub #AWS #Kubernetes #HashiCorpVault #EtherHiding
Keypoints
- ChainDrop began with 11 compromised packages in the keyv and cacheable namespaces.
- More than 500 million weekly downloads were exposed through the infected packages.
- The malware steals secrets from developer workstations and CI/CD environments.
- Stolen credentials are used to infect more NPM packages and GitHub repositories.
- The worm uses EtherHiding, a GitHub-based exfiltration path, and a dead-manβs switch.
Read More: https://www.securityweek.com/over-400-npm-packages-infected-in-chaindrop-supply-chain-attack/