{"id":182783,"date":"2026-08-10T19:40:40","date_gmt":"2026-08-10T17:40:40","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov"},"modified":"2026-08-12T20:28:40","modified_gmt":"2026-08-12T18:28:40","slug":"novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov","title":{"rendered":"El nuevo gusano ChainDrop ha afectado a m\u00e1s de 400 paquetes de NPM","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><a href=\"https:\/\/www.stepsecurity.io\/blog\/chaindrop-npm-worm\" rel=\"nofollow\">Confirmado<\/a> un ataque masivo a paquetes en el repositorio NPM, llevado a cabo mediante un nuevo gusano autorreplicante llamado ChainDrop, que inyecta malware en las dependencias. Como resultado del ataque, se publicaron 2212 versiones maliciosas para 444 paquetes. Los paquetes m\u00e1s populares comprometidos, keyv, flat-cache y file-entry-cache, tienen 154, 149.9 y 147.6 millones de descargas por semana, respectivamente.<\/p>\n<p>&nbsp;<\/p>\n<p>El loader del gusano se encontraba en los archivos setup.mjs y Math_Symbol.js, que se ejecutaban mediante un preprocesador de preinstalaci\u00f3n (\"preinstall\": \"node setup.mjs\"), invocado al instalar el paquete afectado. Los scripts mencionados cargaban un runtime leg\u00edtimo de Bun y un c\u00f3digo ofuscado del gusano, que ten\u00eda un tama\u00f1o de 710 KB. Tras la activaci\u00f3n, el gusano buscaba en el sistema y en las variables de entorno tokens de NPM, PyPI, CircleCI, AWS, GCP, Docker, Azure, HashiCorp, Kubernetes (K8s) y otros servicios (en total se analizaron m\u00e1s de 140 rutas de archivos, tipo ~\/.npmrc), adem\u00e1s de analizar la memoria (a trav\u00e9s de \/proc\/\/mem) del entorno de GitHub Actions en busca de tokens y credenciales.<\/p>\n<p>&nbsp;<\/p>\n<p>Si se encontraba un token para acceder al directorio NPM, el gusano publicaba autom\u00e1ticamente nuevas versiones maliciosas para los paquetes en desarrollo en el entorno actual, infectando el \u00e1rbol de dependencias. A diferencia del gusano previamente detectado, <a href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=64377\" rel=\"nofollow\">Shai-Hulud 2.0<\/a> en ChainDrop se implement\u00f3 la t\u00e9cnica EtherHiding para recibir comandos de control a trav\u00e9s de la cadena de bloques p\u00fablica de Ethereum, utilizando cifrado para ocultar la informaci\u00f3n confidencial transmitida al servidor del atacante y asegurando la inserci\u00f3n en los archivos de configuraci\u00f3n de Claude Code, VS Code y GitHub Copilot para consolidar la presencia en el sistema.<\/p>\n<p>&nbsp;<\/p>\n<p>El ataque comenz\u00f3 con la compromisi\u00f3n del proceso de creaci\u00f3n de versiones basado en GitHub Actions para el paquete <a href=\"https:\/\/www.npmjs.com\/package\/keyv\" rel=\"nofollow\">keyv<\/a>, que tiene 154 millones de descargas por semana y se utiliza como dependencia en 1703 paquetes. Los atacantes crearon una nueva versi\u00f3n 6.0.0, inyect\u00e1ndole c\u00f3digo malicioso, y la publicaron utilizando el mecanismo de<a href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=59019\" rel=\"nofollow\">\"Trusted Publishers\"<\/a>y una adecuada <a href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55345\" rel=\"nofollow\">certificaci\u00f3n SLSA.<\/a>Despu\u00e9s de la publicaci\u00f3n, el gusano infect\u00f3 muchos de los paquetes dependientes de keyv, y a su vez comenz\u00f3 a afectar dependencias indirectas.<\/p>\n<p>&nbsp;<\/p>\n<p>Entre los paquetes m\u00e1s populares que fueron infectados por el gusano, que public\u00f3 versiones maliciosas para ellos, est\u00e1n:<\/p>\n<ul>\n<li>flat-cache 6.1.24 (149.8 millones de descargas por semana);<\/li>\n<li>file-entry-cache 11.1.6 (147.5 millones);<\/li>\n<li>cacheable-request 13.0.20 (33.9 millones);<\/li>\n<li>@cacheable\/utils 2.5.1 (8.7 millones);<\/li>\n<li>cacheable 2.5.1 (7.8 millones);<\/li>\n<li>@cacheable\/memory 2.2.1 (7.1 millones);<\/li>\n<li>cache-manager 7.2.10 (4.2 millones);<\/li>\n<li>@cacheable\/node-cache 3.1.2 (1.5 millones).<\/li>\n<\/ul>\n<p>Fuente: <a rel=\"nofollow\" href=\"https:\/\/www.linux.org.ru\/news\/security\/18352803\">linux.org.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM, \u043f\u0440\u043e\u0432\u043e\u0434\u0438\u043c\u0430\u044f \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043d\u043e\u0432\u043e\u0433\u043e \u0441\u0430\u043c\u043e\u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0447\u0435\u0440\u0432\u044f ChainDrop, \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u0433\u043e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0432 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438. \u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u0430\u0442\u0430\u043a\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043e 2212 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u0432\u044b\u043f\u0443\u0441\u043a\u043e\u0432 \u0434\u043b\u044f 444 \u043f\u0430\u043a\u0435\u0442\u043e\u0432. \u041d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0435 \u0438\u0437 \u0441\u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 keyv, flat-cache \u0438 file-entry-cache \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0442 154, 149.9 \u0438 147.6 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u043e\u0432 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a \u0432 \u043d\u0435\u0434\u0435\u043b\u044e. &nbsp; \u0417\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a \u0447\u0435\u0440\u0432\u044f \u0440\u0430\u0437\u043c\u0435\u0449\u0430\u043b\u0441\u044f \u0432 \u0444\u0430\u0439\u043b\u0430\u0445 setup.mjs [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":9,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-182783","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.3 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM, \u043f\u0440\u043e\u0432\u043e\u0434\u0438\u043c\u0430\u044f \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043d\u043e\u0432\u043e\u0433\u043e \u0441\u0430\u043c\u043e\u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0447\u0435\u0440\u0432\u044f ChainDrop.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Emin Berklin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov\" \/>\n\t\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.3\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041d\u043e\u0432\u044b\u0439 \u0447\u0435\u0440\u0432\u044c ChainDrop \u043f\u043e\u0440\u0430\u0437\u0438\u043b \u0431\u043e\u043b\u0435\u0435 400 NPM-\u043f\u0430\u043a\u0435\u0442\u043e\u0432 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM, \u043f\u0440\u043e\u0432\u043e\u0434\u0438\u043c\u0430\u044f \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043d\u043e\u0432\u043e\u0433\u043e \u0441\u0430\u043c\u043e\u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0447\u0435\u0440\u0432\u044f ChainDrop.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-08-10T17:40:40+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-08-12T18:28:40+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 El nuevo gusano ChainDrop ha afectado a m\u00e1s de 400 paquetes de NPM | ProHoster","description":"Se ha registrado un ataque masivo a paquetes en el repositorio NPM, llevado a cabo utilizando un nuevo gusano autorreplicante llamado ChainDrop.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041d\u043e\u0432\u044b\u0439 \u0447\u0435\u0440\u0432\u044c ChainDrop \u043f\u043e\u0440\u0430\u0437\u0438\u043b \u0431\u043e\u043b\u0435\u0435 400 NPM-\u043f\u0430\u043a\u0435\u0442\u043e\u0432 | ProHoster","og:description":"\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM, \u043f\u0440\u043e\u0432\u043e\u0434\u0438\u043c\u0430\u044f \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043d\u043e\u0432\u043e\u0433\u043e \u0441\u0430\u043c\u043e\u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0447\u0435\u0440\u0432\u044f ChainDrop.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-08-10T17:40:40+00:00","article:modified_time":"2026-08-12T18:28:40+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"182783","title":null,"description":null,"keywords":null,"keyphrases":{"focus":[],"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-08-11 06:43:51","updated":"2026-08-11 06:43:51","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/182783","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=182783"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/182783\/revisions"}],"predecessor-version":[{"id":182902,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/182783\/revisions\/182902"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=182783"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=182783"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=182783"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}