ChainDrop npm Worm Hijacks GitHub Actions OIDC to Poison 444 Packages With Valid SLSA Provenance
Brief
A new npm supply-chain campaign, tracked as ChainDrop and also called Mini Shai-Hulud, shows how attackers can turn trusted developer tools into a worm delivery system.
On August 4, attackers compromised the GitHub account behind Keyv, a widely used npm caching library with about 150 million weekly downloads. Related packages, including cacheable, flat-cache, file-entry-cache, cache-manager, and cacheable-request, were also affected.
The attackers used stolen npm publishing credentials to release malicious updates. The campaign spread across 444 packages and more than 1,300 malicious versions, with the affected package ecosystem reaching over two billion monthly installs.
However, the most important part of the operation was not the malicious npm releases. ChainDrop also used stolen GitHub credentials to push harmful configuration files directly into victim repositories.
