FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

ChainDrop Worm: Sophisticated npm Supply Chain Attack Leveraging GitHub Actions and Trusted Publishing

The ChainDrop worm is a self-propagating supply-chain attack that has compromised 444 npm packages, affecting ecosystems with over 2 billion monthly downloads. By compromising high-reputation GitHub accounts, attackers inject malicious code into main branches to trigger automated releases via GitHub Actions. Critically, the use of OpenID Connect (OIDC) through "Trusted Publishing" allows the poisoned packages to arrive with valid provenance and digital signatures, neutralizing traditional integrity checks. The malware employs a multi-stage execution pattern, utilizing the Bun JavaScript runtime to deploy a 710KB obfuscated payload. It utilizes "EtherHiding"—a Command and Control (C2) mechanism leveraging the Ethereum blockchain—to evade network-based detection while targeting cloud credentials, AI-agent configurations, and cryptocurrency keystores.

PolinRider: DPRK Supply Chain Offensive Targeting npm, Claude Code, and GitHub CLI

North Korean state-sponsored actors, associated with the PolinRider operation and Contagious Interview campaign, are executing a multi-vector supply chain offensive targeting the developer ecosystem. By compromising GitHub maintainer accounts and utilizing package impersonation, the actors injected malicious code into npm, Packagist, and Go ecosystems. The campaign specifically targets modern toolchains, including Claude Code and GitHub CLI, to deploy Windows Remote Access Trojans (RATs), Linux native C rootkits, and credential stealers aimed at SSH keys and developer tokens. With over 108 unique malicious packages and extensions identified, the operation seeks persistent high-level access to DevOps environments and AI-assisted coding workflows.

Links:techjacksolutions.com, feeds.feedburner.com, Medium LLM Security Tag, threat-modeling.com, gbhackers.com, News4Hackers, The Register - Security, Google Cloud Security Community, malware-log.hatenablog.com, xploitzone.com, cybersecurity.pk, cyberscoop.com, SC Media, threatlabsnews.xcitium.com, arXiv (Computer Science - Cryptography and Security), Malware News, serisec.com, The Record by Recorded Future, falconinternet.net, DEV Community, eSecurity Planet, ox.security, Hack Noon, phoenix.security, Microsoft Security Blog, SOCFortress, arcticwolf.com, unit42.paloaltonetworks.com, sec-tec.co.uk, computerweekly.com, bleepingcomputer.com, penligent.ai, SecurityWeek, cloudblog.withgoogle.com, Unit42, Arcticwolf, Threatlocker, Microsoft, Tenable Blog, Osintsights, Cybersecurity News, Sonatype, Daily, Threats, Developer-tech, Ground, Cyberpress, Bellatorcyber, Github, Darkreading, Podcasts, Mallory, Breached, Youtube, Socket, Reddit, Medium, Bighatgroup, Oday-bakkour, Code, Learn, Morphllm, Sqmagazine, Infosecurity-magazine, Devops, Secarma, Ienvi, Innovatecybersecurity, Elastic, Blog, Panther, Stairwell, Socdefenders, Cybersecuritynews, Kudelskisecurity, News, Fag-consult, Ourservices, Kahutek, Isc2gauteng, Agentbreach, About, Pentagondesign, helpnetsecurity.com, Corelight, Flashpoint, Flare, Trmlabs, Margin, Justice, Home, Revanthselvam, Anthropic, Bleepingcomputer, Techzine, Trendmicro, cybersecuritydive.com, Aws, Seceon, Neworleanscitybusiness, Esecurityplanet, Nextgov, Safedep, Thehackernews, Interlynk, Aiweekly, Utopiats, Meritalk, news.ycombinator.com, Splunk, Research, Expel, Strobes, Securitylabs, Wiz, Securityboulevard, Thenextweb, Upwind, Finanzwire, Digital, Openai, Sygnia, Xygeni, Stepsecurity, Labs, Beazley, Cycode, Cloudsmith, Veracode, Zscaler, Hivepro, Ampcuscyber, Sangfor, Falconfeeds, Arxiv, Truefoundry, Businessinsider, Platform, Infoq, Stocktitan, Swif, Subtlerealityshift, Group-ib, Crowdstrike, Dark Reading

Lazarus Group's Brandjacking Campaign targeting the npm Ecosystem

The Lazarus Group has shifted from traditional typosquatting to "brandjacking" within the npm ecosystem, deploying multi-stage droppers disguised as utilities for popular libraries like React, Buffer, and Chai. These malicious packages execute Base64-encoded strings to fetch a second-stage Node.js backdoor from jsonkeeper.com, which subsequently connects to a C2 server (45.59.163.198:1244) to deploy a final payload (f.js) into the ~/.vscode directory. By utilizing npm install --silent for dependency resolution, the attackers establish persistent remote code execution (RCE) on developer workstations, posing a critical risk to CI/CD pipelines and source code repositories.


LINK COPIED TO CLIPBOARD