{"id":182783,"date":"2026-08-10T19:40:40","date_gmt":"2026-08-10T17:40:40","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov"},"modified":"2026-08-12T20:28:40","modified_gmt":"2026-08-12T18:28:40","slug":"novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov","title":{"rendered":"Il nuovo worm ChainDrop ha colpito oltre 400 pacchetti NPM","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><a href=\"https:\/\/www.stepsecurity.io\/blog\/chaindrop-npm-worm\" rel=\"nofollow\">Registrato<\/a> un attacco di massa ai pacchetti nel repository NPM, condotto utilizzando un nuovo worm autoriproducente chiamato ChainDrop, che inserisce malware nelle dipendenze. A seguito dell'attacco sono stati pubblicati 2212 rilasci dannosi per 444 pacchetti. I pacchetti compromessi pi\u00f9 popolari, keyv, flat-cache e file-entry-cache, hanno rispettivamente 154, 149.9 e 147.6 milioni di download a settimana.<\/p>\n<p>&nbsp;<\/p>\n<p>Il loader del worm era situato nei file setup.mjs e Math_Symbol.js, che venivano eseguiti tramite un preinstall handler (&#171;preinstall&#187;: &#171;node setup.mjs&#187;), attivato durante l'installazione del pacchetto compromesso. Gli script sopra citati caricavano un runtime Bun legittimo e il codice obfuscato del worm, della dimensione di 710 KB. Dopo l'attivazione, il worm cercava nel sistema e nelle variabili ambientali token per NPM, PyPI, CircleCI, AWS, GCP, Docker, Azure, HashiCorp, KubernetesK8s e altri servizi (venivano analizzati oltre 140 percorsi di file, come ~\\\/ .npmrc), e analizzava anche la memoria (attraverso \\\/proc\\\/\\\/mem) dell'ambiente GitHub Actions alla ricerca di token e credenziali.<\/p>\n<p>&nbsp;<\/p>\n<p>Se il worm trovava un token per accedere al catalogo NPM, pubblicava automaticamente nuovi rilasci dannosi per i pacchetti in fase di sviluppo nell'ambiente corrente, infettando l'albero delle dipendenze. A differenza del worm precedentemente identificato <a href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=64377\" rel=\"nofollow\">Shai-Hulud 2.0<\/a> in ChainDrop \u00e8 stata implementata la tecnica EtherHiding per ricevere comandi di gestione tramite il blockchain pubblico di Ethereum, utilizzando la crittografia per nascondere i dati sensibili trasmessi al server degli attaccanti e garantendo l'inserimento nei file di configurazione di Claude Code, VS Code e GitHub Copilot per consolidare la presenza nel sistema.<\/p>\n<p>&nbsp;<\/p>\n<p>L'attacco \u00e8 iniziato con la compromissione del processo di generazione dei rilasci basato su GitHub Actions per il pacchetto <a href=\"https:\/\/www.npmjs.com\/package\/keyv\" rel=\"nofollow\">keyv<\/a>, che conta 154 milioni di download a settimana ed \u00e8 utilizzato come dipendenza in 1703 pacchetti. Gli attaccanti hanno creato una nuova versione 6.0.0, inserendo codice dannoso, e l'hanno pubblicata utilizzando il meccanismo di \"<a href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=59019\" rel=\"nofollow\">Trusted Publishers<\/a>\" e una corretta <a href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55345\" rel=\"nofollow\">certificazione SLSA<\/a>. Dopo la pubblicazione, il worm ha infettato molti pacchetti dipendenti da keyv e, in catena, ha iniziato a colpire le dipendenze indirette.<\/p>\n<p>&nbsp;<\/p>\n<p>Tra i pacchetti pi\u00f9 popolari colpiti dal worm che ha pubblicato rilasci dannosi per essi ci sono:<\/p>\n<ul>\n<li>flat-cache 6.1.24 (149.8 milioni di download a settimana);<\/li>\n<li>file-entry-cache 11.1.6 (147.5 milioni);<\/li>\n<li>cacheable-request 13.0.20 (33.9 milioni);<\/li>\n<li>@cacheable\/utils 2.5.1 (8.7 milioni);<\/li>\n<li>cacheable 2.5.1 (7.8 milioni);<\/li>\n<li>@cacheable\/memory 2.2.1 (7.1 mln);<\/li>\n<li>cache-manager 7.2.10 (4.2 mln);<\/li>\n<li>@cacheable\/node-cache 3.1.2 (1.5 mln).<\/li>\n<\/ul>\n<p>Fonte: <a rel=\"nofollow\" href=\"https:\/\/www.linux.org.ru\/news\/security\/18352803\">linux.org.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM, \u043f\u0440\u043e\u0432\u043e\u0434\u0438\u043c\u0430\u044f \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043d\u043e\u0432\u043e\u0433\u043e \u0441\u0430\u043c\u043e\u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0447\u0435\u0440\u0432\u044f ChainDrop, \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u0433\u043e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0432 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438. \u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u0430\u0442\u0430\u043a\u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u043e 2212 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u0432\u044b\u043f\u0443\u0441\u043a\u043e\u0432 \u0434\u043b\u044f 444 \u043f\u0430\u043a\u0435\u0442\u043e\u0432. \u041d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0435 \u0438\u0437 \u0441\u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 keyv, flat-cache \u0438 file-entry-cache \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0442 154, 149.9 \u0438 147.6 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u043e\u0432 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a \u0432 \u043d\u0435\u0434\u0435\u043b\u044e. &nbsp; \u0417\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a \u0447\u0435\u0440\u0432\u044f \u0440\u0430\u0437\u043c\u0435\u0449\u0430\u043b\u0441\u044f \u0432 \u0444\u0430\u0439\u043b\u0430\u0445 setup.mjs [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":9,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-182783","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM, \u043f\u0440\u043e\u0432\u043e\u0434\u0438\u043c\u0430\u044f \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043d\u043e\u0432\u043e\u0433\u043e \u0441\u0430\u043c\u043e\u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0447\u0435\u0440\u0432\u044f ChainDrop.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Emin Berklin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041d\u043e\u0432\u044b\u0439 \u0447\u0435\u0440\u0432\u044c ChainDrop \u043f\u043e\u0440\u0430\u0437\u0438\u043b \u0431\u043e\u043b\u0435\u0435 400 NPM-\u043f\u0430\u043a\u0435\u0442\u043e\u0432 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM, \u043f\u0440\u043e\u0432\u043e\u0434\u0438\u043c\u0430\u044f \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043d\u043e\u0432\u043e\u0433\u043e \u0441\u0430\u043c\u043e\u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0447\u0435\u0440\u0432\u044f ChainDrop.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-08-10T17:40:40+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-08-12T18:28:40+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Il nuovo worm ChainDrop ha colpito oltre 400 pacchetti NPM | ProHoster","description":"\u00c8 stata registrata un'attacco massivo ai pacchetti nel repository NPM, condotto utilizzando un nuovo worm autoriproduttivo ChainDrop.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041d\u043e\u0432\u044b\u0439 \u0447\u0435\u0440\u0432\u044c ChainDrop \u043f\u043e\u0440\u0430\u0437\u0438\u043b \u0431\u043e\u043b\u0435\u0435 400 NPM-\u043f\u0430\u043a\u0435\u0442\u043e\u0432 | ProHoster","og:description":"\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM, \u043f\u0440\u043e\u0432\u043e\u0434\u0438\u043c\u0430\u044f \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043d\u043e\u0432\u043e\u0433\u043e \u0441\u0430\u043c\u043e\u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0449\u0435\u0433\u043e\u0441\u044f \u0447\u0435\u0440\u0432\u044f ChainDrop.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/novyj-cherv-chaindrop-porazil-bolee-400-npm-paketov","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-08-10T17:40:40+00:00","article:modified_time":"2026-08-12T18:28:40+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"182783","title":null,"description":null,"keywords":null,"keyphrases":{"focus":[],"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-08-11 06:43:51","updated":"2026-08-11 06:43:51","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/182783","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=182783"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/182783\/revisions"}],"predecessor-version":[{"id":182902,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/182783\/revisions\/182902"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=182783"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=182783"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=182783"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}