FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Npm Supply Chain: The ChainDrop Worm Evolution

The ChainDrop worm represents a sophisticated evolution of the Shai-Hulud malware, targeting the npm ecosystem through a multi-stage supply chain attack. Unlike traditional package poisoning, ChainDrop achieves stealth by injecting malicious payloads directly into npm tarballs, effectively bypassing source code audits of GitHub repositories. The worm utilizes npm preinstall hooks and exploits developer environments by weaponizing IDE and AI configuration files, specifically .vscode/tasks.json and .claude/settings.json. By compromising over 444 packages—including widely used dependencies like keyv and cache-manager—the malware facilitates credential theft, environment variable exfiltration, and automated self-propagation across developer workstations and CI/CD pipelines.

Massive Shai-Hulud Supply Chain Campaign Compromises npm Ecosystem, Including keyv and cacheable

The "Shai-Hulud" campaign (specifically the "ChainDrop" wave) is a sophisticated supply chain attack targeting the npm ecosystem via hijacked maintainer accounts for widely used packages like keyv and cacheable. Utilizing malicious npm preinstall scripts, the threat actor deploys a self-propagating "Mini Shai-Hulud" worm and an infostealer. The attack leverages OIDC provenance to bypass integrity checks and employs obfuscated JavaScript files, such as math_init.js and Math_Symbol.js, to exfiltrate AWS credentials, GitHub tokens, Kubernetes secrets, and CI/CD environment variables. With over 440 compromised packages and 2 billion monthly downloads at risk, the campaign facilitates deep transitive infection across developer workstations and cloud infrastructure.

Multi-Vector Supply Chain Campaign: Mastra AI, GitHub Actions, and Arch Linux AUR Compromise

A sophisticated supply chain campaign, attributed to the suspected threat actor TeamPCP, has simultaneously targeted the Mastra AI framework via npm, GitHub Actions CI/CD workflows, and the Arch Linux User Repository (AUR). The attack utilized dormant contributor account takeovers to poison the @mastra npm scope using the easy-day-js dependency and hijacked GitHub Action version tags to exfiltrate CI/CD credentials. Additionally, over 1,500 AUR packages were compromised with eBPF-based rootkit malware. This coordinated infrastructure, linked by the "Mini Shai-Hulud" worm, facilitates widespread code execution, credential theft, and persistent rootkit deployment across development, DevOps, and end-user Linux environments.


LINK COPIED TO CLIPBOARD