FILTERING BY: CLEAR FILTER

Npm Ecosystem: Analysis of the ChainDrop Self-Propagating Worm

The ChainDrop worm, part of the Shai-Hulud campaign, is a self-propagating supply chain attack targeting the npm registry. Following the compromise of maintainer accounts, specifically for the keyv and cacheable packages, the worm utilizes malicious preinstall hooks to execute code within CI/CD environments. By targeting GitHub Actions runners, the malware extracts sensitive environment variables and secrets, which are then leveraged to autonomously republish malicious versions of other packages owned by the compromised maintainer. Uniquely, the attackers employ Ethereum smart contracts as a Command and Control (C2) routing mechanism to evade traditional network-based detection and maintain infrastructure persistence.


LINK COPIED TO CLIPBOARD