EXECUTIVE SUMMARY
A threat actor is behind a supply chain attack targeting the npm ecosystem, specifically aiming to steal credentials and disrupt development workflows. The attacker compromises maintainer accounts, publishes poisoned packages, and uses the stolen credentials to further spread the malware, ultimately seeking to gain control over sensitive information and systems. The attack has already affected over 400 packages and 2,000 versions, making it a significant concern for organizations relying on these packages.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A threat actor is behind a supply chain attack targeting the npm ecosystem, specifically aiming to steal credentials and disrupt development workflows. The attacker compromises maintainer accounts, publishes poisoned packages, and uses the stolen credentials to further spread the malware, ultimately seeking to gain control over sensitive information and systems. The attack has already affected over 400 packages and 2,000 versions, making it a significant concern for organizations relying on these packages.[emaillocker id="1283"]
The malware infects systems through a preinstall script that downloads a legitimate JavaScript runtime, which then executes a second-stage payload that steals credentials, publishes more malicious packages, and burrows into developer tooling. The attacker maintains control by using an Ethereum blockchain-based command and control infrastructure, making it challenging to detect and track the malicious activity. As the malware spreads, it adapts and evolves, using the compromised credentials to publish new malicious packages and further expand its reach.
This threat is significant for organizations because it can lead to widespread compromise of development environments, CI/CD pipelines, and sensitive information. The attack's use of legitimate infrastructure and valid provenance attestations makes it difficult to detect, and the fact that it can spread rapidly through automated workflows increases the risk of severe disruption. To defend against this threat, organizations should take immediate action to audit their dependencies, rotate credentials, and monitor for suspicious activity, as well as implement measures to prevent similar attacks in the future, such as enforcing secure coding practices and regularly reviewing package updates.
THREAT PROFILE:
| Tactic | Technique ID | Technique | Sub-technique |
| Initial Access | T1078.004 | Valid Accounts | Cloud Accounts |
| Initial Access | T1195.001 | Supply Chain Compromise | Compromise Software Dependencies and Development Tools |
| Execution | T1059.007 | Command and Scripting Interpreter | JavaScript |
| Persistence | T1547 | Boot or Logon Autostart Execution | — |
| Credential Access | T1552.001 | Unsecured Credentials | Credentials In Files |
| Command and Control | T1105 | Ingress Tool Transfer | — |
| Resource Development | T1608.003 | Stage Capabilities | Install Digital Certificate |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | — |
REFERENCES:
The reports contain further technical details:
https://www.stepsecurity.io/blog/chaindrop-npm-worm