ChainDrop Worm Infects 400+ npm Packages to Steal GitHub and Cloud Credentials

The ChainDrop worm has compromised over 400 npm packages to exfiltrate GitHub credentials, cloud secrets, and other sensitive development data. This supply chain attack uses obfuscated code and Ethereum-based command infrastructure to maintain persistence and infect downstream projects.

Edward Kiledjian @ekiledjian