Critical

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

SecurityWeek
Actively Exploited

Overview

A recent supply chain attack, dubbed the ChainDrop incident, has compromised over 400 NPM packages. The malware involved is designed to steal sensitive information and spread itself by using stolen NPM and GitHub credentials. This incident affects developers who rely on these packages, as the malicious software can infiltrate their projects and lead to further security breaches. The attack's implications are significant, as it underscores the vulnerabilities present in software supply chains, making it crucial for developers to enhance their security practices and monitor their dependencies closely. Users of affected packages need to be vigilant about potential data leaks and the integrity of their code.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Over 400 NPM packages, GitHub credentials
  • Action Required: Developers should audit their NPM packages, change compromised credentials, and monitor for unusual activity in their projects.
  • Timeline: Newly disclosed

Original Article Summary

The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek.

Impact

Over 400 NPM packages, GitHub credentials

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Developers should audit their NPM packages, change compromised credentials, and monitor for unusual activity in their projects.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Malware.

Related Coverage

US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks

Infosecurity Magazine

The U.S. government has imposed sanctions on several individuals linked to the Mabna Institute, a hacking group based in Iran known for cyber-attacks. This group has been involved in various hacking activities, including stealing data from universities and businesses around the world. The sanctions target the group's members to disrupt their operations and deter similar actions in the future. By penalizing these individuals, the U.S. aims to hold them accountable for their cyber activities that threaten both national security and economic interests. This move also signals to other state-sponsored hacking groups that there are consequences for such cyber crimes.

Aug 25, 2026

U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog

Security Affairs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a serious vulnerability in Oracle's HTTP Server and Weblogic Server Proxy Plug-in to its Known Exploited Vulnerabilities catalog. This flaw, identified as CVE-2026-21962, carries a maximum severity score of 10.0, indicating it is a critical risk for users. The vulnerability allows unauthenticated attackers to exploit the affected systems, which could potentially lead to unauthorized access and control. Organizations using these Oracle products should take immediate action to assess their systems and implement necessary security measures to mitigate this risk. The inclusion in CISA's catalog suggests that this vulnerability is being actively targeted by malicious actors, making swift remediation essential.

Aug 25, 2026

Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown

Security Affairs

Despite a recent takedown of its command-and-control servers, the WeedHack malware is still being distributed through fake Minecraft client websites. McAfee Labs reported that there are currently ten active malicious sites, along with several file-hosting accounts, that continue to spread this infostealer. The attackers are using SEO poisoning techniques to ensure these harmful downloads appear at the top of Google search results, making it easier for unsuspecting users to find them. This ongoing campaign puts Minecraft players at risk, as they may unknowingly download software that compromises their personal information and gaming accounts. The persistence of these sites even after efforts to disrupt the malware's infrastructure underscores the need for users to be vigilant about where they download software from.

Aug 25, 2026

AI supply chain risk is showing up in developer workflows first

Help Net Security

In a recent interview, Dr. Jaushin Lee, CEO of Zentera Systems, pointed out that AI supply chain risks are primarily affecting developer workflows and open-source package repositories. He noted that while some issues like poisoned model weights and compromised servers are mainly seen in research settings, the real-world impact is felt in the everyday work of developers. Dr. Lee emphasized that companies might gain more risk reduction from proper segmentation of their systems than from investing heavily in new tools. He also mentioned the shortcomings of self-hosting AI models and suggested that software teams could benefit by adopting certain semiconductor isolation practices. This conversation brings attention to the evolving risks in AI development and the need for better security practices in software development environments.

Aug 25, 2026

New TCG guidance gives buyers a way to test PQC-ready TPM claims

Help Net Security

The Trusted Computing Group (TCG) has released new guidelines for Trusted Platform Modules (TPMs), which are essential components that secure a device's cryptographic keys and firmware integrity. These guidelines specifically address how TPMs can be deemed quantum-safe, a growing concern as quantum computing technology advances. Now, buyers can request proof from vendors that their TPMs meet these new standards, ensuring they are prepared for future quantum threats. This is significant for companies looking to protect their data from potential quantum attacks, as it provides a way to verify the security claims made by manufacturers. The move aims to enhance the overall security landscape as businesses transition to quantum-resistant technology.

Aug 25, 2026

ShinyHunters claims social engineering attack against ReliaQuest

SCM feed for Latest

A group known as ShinyHunters claims to have executed a social engineering attack against ReliaQuest. The attackers targeted employees by calling them and attempting to deceive them into visiting a fraudulent single sign-on (SSO) page. This fake page was hosted on a lookalike domain, reliaquest[.]claims, designed to mimic the legitimate ReliaQuest site. Such tactics can lead to credential theft and unauthorized access to sensitive company data. This incident raises concerns about the effectiveness of security training and awareness among employees, as social engineering remains a prevalent threat in cybersecurity.

Aug 24, 2026