ChainDrop is a self-propagating malware campaign that has compromised more than 1,300 npm packages with about 2 billion monthly downloads, including widely used libraries like Keyv, Cacheable, flat-cache, and file-entry-cache. The attack spread through a maintainer’s GitHub account compromise and used legitimate GitHub Actions releases to deliver infostealing payloads targeting developer, cloud, and CI/CD credentials. #ChainDrop #Keyv #Cacheable #Deliveroo #Ornikar #OneReach #Picsart #Qlik #ServiceTitan
Keypoints
- ChainDrop infected at least 868 packages across 1,381 versions in the npm registry.
- The attack began after the GitHub account of Keyv’s maintainer was compromised.
- Malicious releases were published through legitimate GitHub Actions workflows with valid provenance.
- The payload used setup.mjs to download Bun and run Math_Symbol.js or math_init.js for data theft.
- The malware stole tokens, secrets, cloud credentials, and other sensitive data from developer systems and CI/CD runners.