ChainDrop supply chain compromise: Anatomy of a self-propagating worm (opens in a new tab)
Why readOver 400 npm packages across unrelated publishers, including keyv, flat-cache and cache-manager, were trojanised with a self-propagating credential-stealing worm that fires on preinstall.
A Mini Shai-Hulud variant was pushed into 400+ npm packages spanning multiple publishers, delivered as a heavily obfuscated Bun-based payload that executes via the npm preinstall lifecycle hook before installation finishes. It harvests npm, GitHub, AWS, Kubernetes and HashiCorp Vault credentials from developer workstations and CI/CD runners, then reuses those identities to enumerate and republish packages, propagating itself. Microsoft publishes IOCs, Defender XDR detections and advanced hunting queries; anyone with a lockfile touching the affected trees needs to audit installs and rotate CI tokens now.
Also covered byDatadog Security Labs (opens in a new tab).