Facebook
Britain's News Portal
Around The Clock
BREAKING
Loading latest headlines…

ChainDrop worm poisons 444 npm packages, evades standard defenses

A worm named ChainDrop has been found in the npm supply chain, poisoning 444 packages and spreading via tarballs and dev-tool hooks.

  • ChainDrop is a worm that has poisoned 444 packages in the npm ecosystem.
  • It spreads through tarballs and dev-tool hooks.
  • It evades standard defenses.

A new worm called ChainDrop has been discovered in the npm supply chain, affecting 444 packages. The worm spreads through tarballs and dev-tool hooks, and is able to evade standard security defenses.

The variant, named Shai-Hulud, is reported to have poisoned the packages, raising concerns about the integrity of the npm ecosystem.

Why this matters: The worm's ability to evade standard defenses and spread through dev-tool hooks could have significant implications for software supply chain security.

What this means for you: Developers using npm packages should be aware of the potential risk and review their dependencies for signs of compromise.

Related Articles

Get the news that matters.

Join thousands of readers getting the best of British news straight to their inbox.