BleepingComputer · Bill Toulas ·
Researchers: ChainDrop, a Shai-Hulud-based worm, has compromised 1,300+ npm packages, like Keyv, Cacheable, and flat-cache, with a combined 2B monthly downloads
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.
Lead Source
More
Aikido Security's Blog: Aikido Security's Blog
Socket: Socket
Step Security Blog: Step Security Blog
CSO: CSO
wiz.io: wiz.io
CyberScoop: CyberScoop
The Hacker News: The Hacker News
Microsoft Security Blog: Microsoft Security Blog
OX Security: OX Security
NullTX: NullTX
eSecurity Planet: eSecurity Planet
DevOps.com: DevOps.com
Developer Tech News: Developer Tech News
Datadog Security Labs: Datadog Security Labs