step-security · Crawled Aug 4, 2026
ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2
2 IoCs
Read original article ↗
AI Summary
A self-propagating worm dubbed ChainDrop is actively compromising npm packages by publishing malicious versions using stolen maintainer credentials. The malicious packages include heavily obfuscated files such as setup.mjs and math_init.js, which execute during installation via preinstall scripts, enabling credential harvesting in CI/CD environments. The worm uses Ethereum-based dead-drop command-and-control infrastructure, and over 435 packages with more than 1,550 compromised versions have been identified since August 4, 2026. Organizations using affected packages should assume compromise and rotate all associated credentials and secrets.
AI-extracted · verify before operational use