Shai-Hulud is back in the npm ecosystem, and this time its reach is unusually broad. A new self-propagating malware strain called CHAINDROP has backdoored more than 400 packages after attackers compromised the maintainer of the widely used keyv library. The campaign turns trusted software updates into a route for stealing developer credentials and spreading further. It can run before installation is complete, then use captured npm access tokens to publish altered versions of every package a victim is allowed to update. Elastic Security Labs identified the activity on August 4, describing an attack that began with keyv’s monorepo and expanded rapidly. The affected package set totals more than 1.3 billion monthly...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!