ChainDrop is more than a malicious npm package outbreak: its worm can steal CI/CD credentials, abuse GitHub Actions OIDC publishing access, and plant persistence in Claude and Visual Studio Code repositories. Microsoft says organizations that installed an affected release should treat developer workstations and build runners as compromised, even if the package has since been removed. Source
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!