{"id":182783,"date":"2026-08-10T19:40:40","date_gmt":"2026-08-10T17:40:40","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov"},"modified":"2026-08-10T19:40:40","modified_gmt":"2026-08-10T17:40:40","slug":"novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov","title":{"rendered":"Il nuovo worm ChainDrop ha colpito oltre 400 pacchetti NPM","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex>          <a rel=\"nofollow\" id=\"memories_button\" href=\"#\" title=\"Monitorare\"><i class=\"icon-bell\"><\/i><\/a><br \/>1                            <noindex><\/p>\n<p><a rel=\"nofollow\" href=\"https:\/\/www.stepsecurity.io\/blog\/chaindrop-npm-worm\">Registrato<\/a> un attacco di massa sui pacchetti nel repository NPM, condotto utilizzando un nuovo worm auto-replicante ChainDrop, che inserisce malware nelle dipendenze. A seguito dell'attacco, sono stati pubblicati 2212 rilasci malevoli per 444 pacchetti. I pacchetti compromessi pi\u00f9 popolari, keyv, flat-cache e file-entry-cache, hanno registrato rispettivamente 154, 149,9 e 147,6 milioni di download a settimana.<\/p>\n<p><\/noindex>  <\/p>\n<p>Il caricatore del worm si trovava nei file setup.mjs e Math_Symbol.js, che venivano eseguiti tramite un preinstall handler (\"preinstall\": \"node setup.mjs\"), invocato durante l'installazione del pacchetto compromesso. Gli script indicati caricavano un legittimo Bun runtime e il codice offuscato del worm, di dimensione 710 KB. Una volta attivato, il worm cercava nel sistema e nelle variabili d'ambiente i token per NPM, PyPI, CircleCI, AWS, GCP, Docker, Azure, HashiCorp, KubernetesK8s e altri servizi (venivano analizzati oltre 140 percorsi di file, come ~\/.npmrc), e analizzava anche la memoria (attraverso \/proc\/\/mem) dell'ambiente GitHub Actions alla ricerca di token e credenziali.<\/p>\n<p> <noindex><\/p>\n<p>In caso di rilevamento di un token per connettersi al repository NPM, il worm pubblicava automaticamente nuovi rilasci malevoli per i pacchetti in fase di sviluppo nell'attuale ambiente, compromettendo l'albero delle dipendenze. A differenza del worm precedentemente scoperto <a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=64377\">Shai-Hulud 2.0<\/a> , in ChainDrop \u00e8 stata implementata la tecnica EtherHiding per ricevere comandi di gestione attraverso la blockchain pubblica di Ethereum, utilizzando la crittografia per nascondere i dati riservati trasmessi al server degli attaccanti e garantendo l'inserimento nei file di configurazione di Claude Code, VS Code e GitHub Copilot per consolidare la propria presenza nel sistema.<\/p>\n<p><\/noindex> <noindex><\/p>\n<p>L'attacco \u00e8 iniziato con la compromissione del processo di creazione dei rilasci sulla base di GitHub Actions per il pacchetto <a rel=\"nofollow\" href=\"https:\/\/www.npmjs.com\/package\/keyv\">keyv<\/a>, con 154 milioni di download a settimana e utilizzato come dipendenza in 1703 pacchetti. Gli aggressori hanno creato una nuova versione 6.0.0, inserendovi del codice dannoso, e l'hanno pubblicata utilizzando il meccanismo &laquo;<a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=59019\">Trusted Publishers<\/a>&raquo; e corretto <a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55345\">certificazione SLSA<\/a>. Dopo la pubblicazione, il worm ha compromesso molti pacchetti dipendenti da keyv e, a catena, ha iniziato a colpire le dipendenze indirette.<\/p>\n<p><\/noindex> <\/p>\n<p>Tra i pacchetti pi\u00f9 popolari compromessi dal worm, che ha pubblicato per loro rilasci malevoli, si trovano:<\/p>\n<ul>\n<li>flat-cache 6.1.24 (149,8 milioni di download a settimana);<\/li>\n<li>file-entry-cache 11.1.6 (147,5 milioni);<\/li>\n<li>cacheable-request 13.0.20 (33,9 milioni);<\/li>\n<li>@cacheable\/utils 2.5.1 (8,7 milioni);<\/li>\n<li>cacheable 2.5.1 (7,8 milioni);<\/li>\n<li>@cacheable\/memory 2.2.1 (7,1 milioni);<\/li>\n<li>cache-manager 7.2.10 (4,2 milioni);<\/li>\n<li>@cacheable\/node-cache 3.1.2 (1,5 milioni).<\/li>\n<\/ul>\n<p>Fonte: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.linux.org.ru\/news\/security\/18352803\">linux.org.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>1 \u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM, \u043f\u0440\u043e\u0432\u043e\u0434\u0438\u043c\u0430\u044f \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043d\u043e\u0432\u043e\u0433\u043e \u0441\u0430\u043c\u043e\u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0447\u0435\u0440\u0432\u044f ChainDrop, \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u0433\u043e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0432 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438. \u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u0430\u0442\u0430\u043a\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043e 2212 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u0432\u044b\u043f\u0443\u0441\u043a\u043e\u0432 \u0434\u043b\u044f 444 \u043f\u0430\u043a\u0435\u0442\u043e\u0432. \u041d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0435 \u0438\u0437 \u0441\u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 keyv, flat-cache \u0438 file-entry-cache \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0442 154, 149.9 \u0438 147.6 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u043e\u0432 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a \u0432 \u043d\u0435\u0434\u0435\u043b\u044e. \u0417\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a \u0447\u0435\u0440\u0432\u044f \u0440\u0430\u0437\u043c\u0435\u0449\u0430\u043b\u0441\u044f \u0432 \u0444\u0430\u0439\u043b\u0430\u0445 setup.mjs [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":9,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-182783","post","type-post","status-publish","format-standard","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"1 \u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Emin Berklin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041d\u043e\u0432\u044b\u0439 \u0447\u0435\u0440\u0432\u044c ChainDrop \u043f\u043e\u0440\u0430\u0437\u0438\u043b \u0431\u043e\u043b\u0435\u0435 400 NPM-\u043f\u0430\u043a\u0435\u0442\u043e\u0432 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"1 \u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-08-10T17:40:40+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-08-10T17:40:40+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Il nuovo worm ChainDrop ha colpito oltre 400 pacchetti NPM | ProHoster","description":"1 Confermato.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041d\u043e\u0432\u044b\u0439 \u0447\u0435\u0440\u0432\u044c ChainDrop \u043f\u043e\u0440\u0430\u0437\u0438\u043b \u0431\u043e\u043b\u0435\u0435 400 NPM-\u043f\u0430\u043a\u0435\u0442\u043e\u0432 | ProHoster","og:description":"1 \u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430.","og:url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-08-10T17:40:40+00:00","article:modified_time":"2026-08-10T17:40:40+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/182783","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=182783"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/182783\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=182783"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=182783"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=182783"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}