As cited
Copy frozen at (site build).
threat intel
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting over 400 packages across multiple publishers, delivering a self-propagating credential-stealing worm called Mini Shai-Hulud through obfuscated JavaScript payloads. The malware executes via npm preinstall hooks before package installation completes, searches for and exfiltrates npm, GitHub, AWS, Kubernetes, and vault credentials, then automatically republishes compromised packages to propagate itself. Organizations using affected packages should treat developer workstations and CI/CD systems as potentially compromised and immediately revoke and rotate all exposed credentials.
Why it matters: Any organization using npm packages from affected publishers risks credential theft, unauthorized package republication, and supply chain propagation; immediate action to identify installed versions, audit credential exposure, and rebuild systems from trusted sources is required.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
Microsoft Threat Intelligence identified a large-scale npm supply chain attack compromising over 400 packages through malicious patch releases containing a self-propagating worm variant called Mini Shai-Hulud. The obfuscated JavaScript payload executes via npm preinstall hooks, harvests credentials from developer machines and CI/CD environments, and automatically republishes infected packages to amplify the attack across the ecosystem. Affected organizations should treat compromised workstations and build systems as breached and immediately revoke credentials, rotate secrets, and rebuild artifacts from trusted sources.
Why it matters: Any organization using affected npm packages (keyv, flat-cache, cache-manager, and hundreds of others) with lifecycle scripts enabled faces immediate credential theft and supply chain propagation risk; prioritize detecting unauthorized package releases, repository modifications, and credential exfiltration.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
Microsoft Threat Intelligence identified a large-scale npm supply chain attack compromising over 400 packages through malicious patch releases containing a self-propagating worm variant called Mini Shai-Hulud. The obfuscated JavaScript payload executes via npm preinstall hooks, harvests credentials from developer machines and CI/CD environments, and automatically republishes infected packages to amplify the attack across the ecosystem. Affected organizations should treat compromised workstations and build systems as breached and immediately revoke credentials, rotate secrets, and rebuild artifacts from trusted sources.
Why it matters: Any organization using affected npm packages (keyv, flat-cache, cache-manager, and hundreds of others) with lifecycle scripts enabled faces immediate credential theft and supply chain propagation risk; prioritize detecting unauthorized package releases, repository modifications, and credential exfiltration.
- Source published
- First seen by Cybersecurity Tracker