• Aikido researchers uncovers ChainDrop, a Shai‑Hulud variant infecting 1,300+ npm packages with an infostealer
  • Attackers compromised GitHub accounts tied to popular libraries (Keyv, Cacheable, flat‑cache, file‑entry‑cache) and pushed tainted releases with 2B monthly downloads
  • Malware exfiltrates developer/cloud credentials and secrets to a public GitHub repo; admins should treat affected systems as compromised even after removal

Another Shai-Hulud variant has been discovered in the wild, infecting more than 1,300 npm packages with an infostealer.

Security researchers Aikido reported finding “at least 868 packages (across 1381 versions) that have been compromised by the worm.”



Source link

Podcast also available on PocketCasts, SoundCloud, Spotify, Google Podcasts, Apple Podcasts, and RSS.