The new ChainDrop worm has infected over 400 NPM packages.


1

Recorded A massive attack on packages in the NPM repository was carried out using the new self-propagating ChainDrop worm, which injects malware into dependencies. The attack resulted in 2212 malicious releases for 444 packages. The most popular of the compromised packages—keyv, flat-cache, and file-entry-cache—were downloaded 154, 149.9, and 147.6 million times per week, respectively.

The worm's loader was located in the setup.mjs and Math_Symbol.js files, which were launched using the preinstall handler ("preinstall": "node setup.mjs"), which was called during installation of the infected package. These scripts downloaded the legitimate Bun runtime and obfuscated worm code, 710 KB in size. Once activated, the worm searched the system and environment variables for tokens to NPM, PyPI, CircleCI, AWS, GCP, Docker, Azure, HashiCorp, KubernetesK8s, and other services (more than 140 file paths, such as ~/.npmrc, were analyzed), and also analyzed memory (via /proc/). /mem) of the GitHub Actions environment for tokens and credentials.

If a token for connecting to the NPM directory was detected, the worm automatically published new malicious releases for packages being developed in the current environment, infecting the dependency tree. Unlike the previously detected worm, Shai-Hulud 2.0 ChainDrop implemented the EtherHiding technique to receive control commands through the public Ethereum blockchain, used encryption to hide confidential data transmitted to the attacker's server, and provided injection into the configuration files of Claude Code, VS Code, and GitHub Copilot to secure its presence in the system.

The attack began with a compromise of the release process based on GitHub Actions for the package keyv, which is downloaded 154 million times per week and is used as a dependency in 1703 packages. The attackers created a new version, 6.0.0, with malicious code inserted into it and published it using the "Trusted Publishers» and correct SLSA certificationAfter publication, the worm infected many keyv-dependent packages and then began to infect indirect dependencies.

Among the most popular packages that were affected by the worm, which published malicious releases for them:

  • flat-cache 6.1.24 (149.8 million downloads per week);
  • file-entry-cache 11.1.6 (147.5 million);
  • cacheable-request 13.0.20 (33.9 million);
  • @cacheable/utils 2.5.1 (8.7 million);
  • cacheable 2.5.1 (7.8 million);
  • @cacheable/memory 2.2.1 (7.1 million);
  • cache-manager 7.2.10 (4.2 million);
  • @cacheable/node-cache 3.1.2 (1.5 million).

Source: linux.org.ru

Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster