Mmastodon TechnologySoftware first seen 1 d ago, last 1 d ago, peak #6
ChainDrop attack poisons npm packages via hijacked maintainer account
Original: ChainDrop: attackers hijacked a maintainer's GitHub account and shipped poisoned npm releases with valid provenance. 400
Security researchers are warning about a supply chain attack dubbed ChainDrop, in which attackers took over a package maintainer's GitHub account and published malicious npm releases carrying valid cryptographic provenance. The compromised releases reportedly touched around 400 packages with an estimated two billion weekly downloads. Commentators say the attack shows that provenance attestation works technically but cannot protect against a trusted account being compromised in the first place.
Why now: A major npm supply chain breach with billions of installs is a fresh and serious security concern for developers worldwide.
Evidence
- ChainDrop: attackers hijacked a maintainer's GitHub account and shipped poisoned npm releases with valid provenance. 400 packages, 2B installs. The cryptography worked. The trust assumption underneath it didn't. Our take on the two places to stop it: [ https://… · relayshieldadmin@infosec.exchange · 3
API: https://socialmediatrends-api.osmike.com/v1/trends/1265099