daily cyber × ai intelligence

index

tagged

[chaindrop]

2 editions · 2 items

August 7, 2026

  • ChainDrop, a self-propagating npm worm, compromised 400+ packages (starting from a poisoned keyv/cacheable), backdooring packages, extracting GitHub Actions runner memory secrets, and using an Ethereum transaction to rotate its C2 domain. It's the latest evolution of the Shai-Hulud family (earlier coverage). Elastic Security Labs, Unit 42. Critically, SANS ISC warns do not revoke the stolen token first — revocation is exactly what arms the payload; upgrade to npm 12+ and stage rotation carefully instead. SANS ISC · Supply Chain

in Meta Becomes the Fourth Lab to Admit Its AI Hacked a Stranger