ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Open Source

ChainDrop supply-chain attack spreads via compromised NPM and GitHub credentials

Source headline: Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

Threat level Critical
Signal strength 85/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

A supply-chain campaign dubbed ChainDrop has infected more than 400 NPM packages. The malicious code is designed to steal and exfiltrate sensitive information and then self-propagate. It uses compromised NPM and GitHub credentials to spread across repositories. Developers who install affected packages may unknowingly expose secrets and credentials. Users should review dependencies for ChainDrop-related indicators and consider auditing and tightening package publishing and token access.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#credential-theft #supply-chain #npm #dependency-security #chaindrop
Original reporting SecurityWeek Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
Open original source