Security0 views

ChainDrop Attack Compromises 1,300+ npm Packages With 2 Billion Monthly Downloads

A massive supply chain attack called ChainDrop has compromised over 1,300 npm packages, affecting libraries with a combined 2 billion monthly downloads. Popular packages including Keyv, Cacheable, flat-cache, and file-entry-cache were targeted in the campaign.

The attack distributes a worm-based malware inspired by Shai-Hulud, designed to extract sensitive credentials and data. The malware steals GitHub and npm tokens, AWS credentials, Kubernetes information, and HashiCorp Vault secrets. It also targets financial and service data from platforms including Stripe, Slack, Twilio, Azure, and Google Cloud Platform.

The scope of the compromise is still expanding, as the campaign remains active. A comprehensive list of affected packages and their compromised versions is available on TabNews, though additional packages may be added as the attack continues. The discovery was first reported by BleepingComputer.