ChainDrop: A Supply Chain Worm Stealing Credentials and Self-Propagating via Legitimate Provenance-Signed npm Packages
Aikido Security disclosed a critical npm supply chain attack dubbed ChainDrop, which compromised popular packages including keyv, flat-cache, and file-entry-cache. The attackers hijacked maintainer Gi…