ChainDrop npm Worm Infects Over 400 Packages, Exposing Developer Credentials
A self-propagating npm worm, named ChainDrop, has infected over 400 npm packages, which are collectively downloaded hundreds of millions of times weekly. The worm targets widely used packages such as keyv and cacheable-request, potentially compromising developer workstations, CI pipelines, cloud environments, and downstream software users. Once installed, ChainDrop steals sensitive data including cloud credentials, npm and GitHub tokens, and SSH keys. It can also extract temporary credentials from GitHub Actions runner memory and use stolen npm publishing tokens to infect and republish additional packages. The attack was detected by Unit 42, which observed the worm's execution across 10 distinct environments. The worm uses blockchain-based command-and-control (C2) resolution and can execute additional attacker-supplied code. The adversary reconfigured the worm's C2 infrastructure through a single Ethereum transaction, demonstrating advanced capabilities.