Threat Advisory

ChainDrop npm Worm Package Security Threat

Threat: Malicious Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A threat actor is behind a supply chain attack targeting the npm ecosystem, specifically aiming to steal credentials and disrupt development workflows. The attacker compromises maintainer accounts, publishes poisoned packages, and uses the stolen credentials to further spread the malware, ultimately seeking to gain control over sensitive information and systems. The attack has already affected over 400 packages and 2,000 versions, making it a significant concern for organizations relying on these packages.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A threat actor is behind a supply chain attack targeting the npm ecosystem, specifically aiming to steal credentials and disrupt development workflows. The attacker compromises maintainer accounts, publishes poisoned packages, and uses the stolen credentials to further spread the malware, ultimately seeking to gain control over sensitive information and systems. The attack has already affected over 400 packages and 2,000 versions, making it a significant concern for organizations relying on these packages.[emaillocker id="1283"]

The malware infects systems through a preinstall script that downloads a legitimate JavaScript runtime, which then executes a second-stage payload that steals credentials, publishes more malicious packages, and burrows into developer tooling. The attacker maintains control by using an Ethereum blockchain-based command and control infrastructure, making it challenging to detect and track the malicious activity. As the malware spreads, it adapts and evolves, using the compromised credentials to publish new malicious packages and further expand its reach.

This threat is significant for organizations because it can lead to widespread compromise of development environments, CI/CD pipelines, and sensitive information. The attack's use of legitimate infrastructure and valid provenance attestations makes it difficult to detect, and the fact that it can spread rapidly through automated workflows increases the risk of severe disruption. To defend against this threat, organizations should take immediate action to audit their dependencies, rotate credentials, and monitor for suspicious activity, as well as implement measures to prevent similar attacks in the future, such as enforcing secure coding practices and regularly reviewing package updates.

THREAT PROFILE:

Tactic Technique ID Technique Sub-technique
Initial Access T1078.004 Valid Accounts Cloud Accounts
Initial Access T1195.001 Supply Chain Compromise Compromise Software Dependencies and Development Tools
Execution T1059.007 Command and Scripting Interpreter JavaScript
Persistence T1547 Boot or Logon Autostart Execution
Credential Access T1552.001 Unsecured Credentials Credentials In Files
Command and Control T1105 Ingress Tool Transfer
Resource Development T1608.003 Stage Capabilities Install Digital Certificate
Exfiltration T1041 Exfiltration Over C2 Channel

REFERENCES:

The reports contain further technical details:
https://www.stepsecurity.io/blog/chaindrop-npm-worm

[/emaillocker]
crossmenu