ChainDrop Publishes Initial Malware Without Stealing a Long-Lived npm Token

The ChainDrop campaign has exposed a gap in modern software supply-chain defenses: malware no longer needs a durable npm publishing token or even an npm install event to spread through developer environments. The self-propagating npm worm, also tracked as a Mini Shai-Hulud variant, turned compromised publisher and CI identities into a distribution mechanism while establishing […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: