ChainDrop has turned routine software installs into a route for credential theft. The self-propagating worm infected more than 400 npm packages, putting developer laptops, build systems and cloud environments at risk. Since compromised packages still work as expected, teams may not realize an update has opened a path into their environment. The campaign spreads through trusted publishing accounts. A poisoned package runs during installation, searches for valuable access tokens, and uses stolen npm credentials to alter and republish further packages. That automated cycle lets one compromised developer or build runner affect many downstream users. Unit 42 said in a report shared with Cyber Security News (CSN) that the...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!