A large supply-chain attack targeting the Node Package Manager (npm) registry spreads through malicious packages tied to the “ChainDrop” campaign. Reporting from multiple outlets says the malware is self-propagating and infects hundreds of npm packages, with figures ranging from at least “over 400” infected packages in one report to more than 1,300 compromised packages in another. The scale of distribution is described as substantial, with one source noting that the affected packages collectively receive roughly 2 billion monthly downloads.
The malware’s purpose is described as stealing and exfiltrating secrets from compromised environments. To enable continued spread, the attack also uses stolen credentials, including npm and GitHub access tokens or credentials obtained through compromise. This allows the malware to insert itself into additional packages or deliver updates that propagate the malicious code.
Across the coverage, the common themes are the self-propagating nature of ChainDrop, the use of stolen npm and GitHub credentials for further infection, and the large number of impacted packages on the npm ecosystem.