ChainDrop worm poisons 444 npm packages, evades standard defenses
UKPulse News Desk
A worm named ChainDrop has been found in the npm supply chain, poisoning 444 packages and spreading via tarballs and dev-tool hooks.
- ChainDrop is a worm that has poisoned 444 packages in the npm ecosystem.
- It spreads through tarballs and dev-tool hooks.
- It evades standard defenses.
A new worm called ChainDrop has been discovered in the npm supply chain, affecting 444 packages. The worm spreads through tarballs and dev-tool hooks, and is able to evade standard security defenses.
The variant, named Shai-Hulud, is reported to have poisoned the packages, raising concerns about the integrity of the npm ecosystem.
Why this matters: The worm's ability to evade standard defenses and spread through dev-tool hooks could have significant implications for software supply chain security.
What this means for you: Developers using npm packages should be aware of the potential risk and review their dependencies for signs of compromise.