BleepingComputer · Bill Toulas ·

Researchers: ChainDrop, a Shai-Hulud-based worm, has compromised 1,300+ npm packages, like Keyv, Cacheable, and flat-cache, with a combined 2B monthly downloads

Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.

Researchers: ChainDrop, a Shai-Hulud-based worm, has compromised 1,300+ npm packages, like Keyv, Cacheable, and flat-cache, with a combined 2B monthly downloads

Lead Source

How this story grew

Coverage · 0 Discussion · 0
Aug 4Aug 5

More

Aikido Security's Blog: Aikido Security's Blog
Step Security Blog: Step Security Blog
Microsoft Security Blog: Microsoft Security Blog
Socket: Socket
Infosecurity: Infosecurity
SecurityWeek: SecurityWeek
wiz.io: wiz.io
The Hacker News: The Hacker News
CSO: CSO
CyberScoop: CyberScoop
OX Security: OX Security
Datadog Security Labs: Datadog Security Labs

Discussion