MikeTrendsTrends right now

Mmastodon TechnologySoftware first seen 21 h ago, last 21 h ago, peak #6

ChainDrop attack poisons npm packages via hijacked maintainer account

Original: ChainDrop: attackers hijacked a maintainer's GitHub account and shipped poisoned npm releases with valid provenance. 400

Security researchers are warning about a supply chain attack dubbed ChainDrop, in which attackers took over a package maintainer's GitHub account and published malicious npm releases carrying valid cryptographic provenance. The compromised releases reportedly touched around 400 packages with an estimated two billion weekly downloads. Commentators say the attack shows that provenance attestation works technically but cannot protect against a trusted account being compromised in the first place.

Why now: A major npm supply chain breach with billions of installs is a fresh and serious security concern for developers worldwide.

npmGitHubChainDrop

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1265099