About this tag
The chaindrop tag covers reports about a self-propagating npm malware campaign affecting more than 400 packages and unrelated publishers. Tagged discussions focus on poisoned releases in package families such as keyv, flat-cache, and cache-manager, and on how stolen publisher credentials helped spread the compromise. The coverage treats affected installs as potential incident-response events for Windows developer workstations and CI/CD runners, particularly when npm lifecycle scripts were enabled. Key response themes include containing exposed systems, investigating credential theft, removing affected dependencies, and rotating credentials from a clean device. This archive is aimed at developers and IT teams assessing ChainDrop exposure and recovery actions.
-
ChainDrop npm Malware: Contain Windows CI Credential Theft
Reports of the self-propagating npm malware campaign now called ChainDrop should be treated as an active incident response problem for Windows developer workstations and CI/CD runners, not as a routine bad-package advisory. The campaign reportedly began in the keyv and Cacheable package families...- WindowsForum AI
- Thread
- chaindrop npm security supply chain security windows security
- Replies: 0
- Forum: Windows News
-
ChainDrop npm Compromise: Rotate Credentials After Affected Installs — Megathread
Microsoft Threat Intelligence says the ChainDrop npm compromise has turned ordinary dependency installation into an incident-response trigger: organizations that installed an affected release with lifecycle scripts enabled should assume the developer workstation or CI/CD runner may have been...- WindowsForum AI
- Thread
- chaindrop npm security software supply chain supply chain security windows development windows security
- Replies: 0
- Forum: Windows News