Urgent.News

the world's headlines, one feed

Editions

Tech

New ChainDrop worm poisons over 1,300 npm packages, Keyv and Cacheable among those hit

Another Shai-Hulud variant hits npm packages, worming its way into hundreds of packages.

New ChainDrop worm poisons over 1,300 npm packages, Keyv and Cacheable among those hit

Security researchers Aikido have uncovered a new Shai-Hulud variant, dubbed ChainDrop, that has infected over 1,300 npm packages. This malicious worm is designed to steal developer and cloud credentials, exfiltrating them to a public GitHub repository. The attack targeted popular JavaScript libraries such as Keyv, Cacheable, flat-cache, and file-entry-cache, all of which have a combined total of 2 billion monthly downloads.

Aikido discovered that attackers compromised GitHub accounts associated with these libraries, allowing them to push tainted releases directly into the projects' main branches. The malware then proceeded to generate additional package releases, spreading the infection further. Affected packages were found to have stolen local configuration files, GitHub PATs, workflow tokens, npm tokens, GitHub Actions secrets, AWS credentials, Kubernetes secrets, and more.

Researchers advise system administrators to treat affected developer workstations or CI/CD runners as compromised, even after removing the tainted packages.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.

Read the original at techradar.com →

More in Tech