ChainDrop is more than a malicious npm package outbreak: its worm can steal CI/CD credentials, abuse GitHub Actions OIDC publishing access, and plant persistence in Claude and Visual Studio Code repositories. Microsoft says organizations that installed an affected release should treat developer workstations and build runners as compromised, even if the package has since been removed. Source
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!