Crypto Ticker:
sysadmin from 4sysops.com

ChainDrop npm worm now targets CI/CD OIDC tokens and developer tools

IT News
20 hours ago
1 Views
0 Comments
ChainDrop npm worm now targets CI/CD OIDC tokens and developer tools

ChainDrop is more than a malicious npm package outbreak: its worm can steal CI/CD credentials, abuse GitHub Actions OIDC publishing access, and plant persistence in Claude and Visual Studio Code repositories. Microsoft says organizations that installed an affected release should treat developer workstations and build runners as compromised, even if the package has since been removed. Source

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!