ChainDrop npm Worm Infects Hundreds of Packages, Exposing Developer Credentials
A self-propagating npm worm, dubbed ChainDrop, has infected over 400 packages, affecting developer workstations, CI pipelines, and cloud environments. The worm steals cloud credentials, npm and GitHub tokens, and other sensitive data, using these to spread further by republishing infected packages. The attack has been linked to 453 public GitHub repositories and involves blockchain-based command-and-control infrastructure. The worm's persistence mechanisms include cross-linked files in developer tools like VS Code, and it uses Ethereum smart contracts to rotate command-and-control domains. The attack highlights vulnerabilities in the npm ecosystem and the potential for widespread supply chain compromises.