CYBERSECURITYTRACKER
TRACKING7,256 stories in this site build1,517 vulnerability news stories in this site build
Permanent story citation

ChainDrop: Inside a Self-Propagating npm Worm

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4028

As cited

Copy frozen at (site build).

threat intel

ChainDrop: Inside a Self-Propagating npm Worm

Security researchers analyzed ChainDrop, a self-propagating worm distributed through npm packages that extracts GitHub Actions runner secrets and uses Ethereum smart contracts as a command-and-control mechanism. The worm spreads through supply chain dependencies, enabling attackers to compromise development environments and exfiltrate sensitive credentials.

Why it matters: Developers and DevOps teams relying on npm packages face direct risk of credential theft and environment compromise through a highly automated attack that exploits the trust model of open source dependency chains.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

ChainDrop: Inside a Self-Propagating npm Worm

Security researchers analyzed ChainDrop, a self-propagating worm distributed through npm packages that extracts GitHub Actions runner secrets and uses Ethereum smart contracts as a command-and-control mechanism. The worm spreads through supply chain dependencies, enabling attackers to compromise development environments and exfiltrate sensitive credentials.

Why it matters: Developers and DevOps teams relying on npm packages face direct risk of credential theft and environment compromise through a highly automated attack that exploits the trust model of open source dependency chains.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary