The new worm ChainDrop has affected over 400 NPM packages.

Registered a mass attack on packages in the NPM repository, carried out using a new self-replicating worm called ChainDrop, which injects malware into dependencies. As a result of the attack, 2,212 malicious releases were published for 444 packages. The most popular compromised packages keyv, flat-cache, and file-entry-cache have 154, 149.9, and 147.6 million downloads per week, respectively.

 

The worm's loader was found in the setup.mjs and Math_Symbol.js files, which were executed via a preinstall handler ("preinstall": "node setup.mjs") triggered during the installation of the affected package. These scripts downloaded a legitimate Bun runtime and obfuscated worm code, totaling 710 KB. After activation, the worm searched the system and environment variables for tokens related to NPM, PyPI, CircleCI, AWS, GCP, Docker, Azure, HashiCorp, KubernetesK8s, and other services (analyzing over 140 file paths, such as ~/.npmrc), and scanned memory (through /proc//mem) of the GitHub Actions environment for tokens and credentials.

 

If a token for connecting to the NPM registry was found, the worm automatically published new malicious releases for packages being developed in the current environment, infecting the dependency tree. Unlike the previously discovered worm Shai-Hulud 2.0 , ChainDrop employed EtherHiding techniques to receive commands via the public Ethereum blockchain, used encryption to obscure sensitive data sent to the attack server, and facilitated the insertion of its code into configuration files for Claude Code, VS Code, and GitHub Copilot to maintain its presence in the system.

 

The attack began with the compromise of the release process based on GitHub Actions for the package keyv, which has 154 million downloads per week and is used as a dependency in 1,703 packages. The attackers created a new version 6.0.0, injecting malicious code, and published it using the "Trusted Publishers" mechanism and proper SLSA certification. After publication, the worm affected many packages dependent on keyv and, in turn, began infecting indirect dependencies.

 

Among the most popular packages that were infected by the worm, which published malicious releases for them, are:

  • flat-cache 6.1.24 (149.8 million downloads per week);
  • file-entry-cache 11.1.6 (147.5 million);
  • cacheable-request 13.0.20 (33.9 million);
  • @cacheable/utils 2.5.1 (8.7 million);
  • cacheable 2.5.1 (7.8 million);
  • @cacheable/memory 2.2.1 (7.1 million);
  • cache-manager 7.2.10 (4.2 million);
  • @cacheable/node-cache 3.1.2 (1.5 million).

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster