ChainDrop npm Worm Poisons 444 Packages Through GitHub Actions and Trusted Publishing

ChainDrop has made an npm package compromise a warning about developer machines. The self-propagating campaign poisoned 444 packages and more than 1,300 malicious releases after attackers took over the GitHub account tied to the Keyv caching library. The affected packages represented more than two billion monthly installs. The operation spread through stolen npm publishing tokens […]

This article has been indexed from Cyber Security News

Read the original article: