THE ChainDrop worm has compromised over 430 npm packages that collectively see two billion monthly installs. Initiated on August 4, the attack involved infiltrating a maintainer's GitHub account, allowing attackers to inject a credential-stealing worm into popular packages. This worm is designed to harvest sensitive information like npm tokens and AWS credentials, sending the stolen data to a public GitHub repo.
Security experts recommend immediate actions, including removing affected packages and rotating credentials, to mitigate this threat. The campaign highlights ongoing vulnerabilities within the npm ecosystem.