ChainDrop Worm Infects 400+ npm Packages to Steal GitHub and Cloud Credentials

ChainDrop has turned routine software installs into a route for credential theft. The self-propagating worm infected more than 400 npm packages, putting developer laptops, build systems and cloud environments at risk. Since compromised packages still work as expected, teams may not realize an update has opened a path into their environment. The campaign spreads through […]

This article has been indexed from Cyber Security News

Read the original article: