ChainDrop Malware Infects Over 1,300 npm Packages

BleepingComputer · business

A self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages on the Node Package Manager (npm) registry. These infected packages collectively have over 2 billion monthly downloads. Popular packages like Keyv and Cacheable were among those affected. This widespread attack highlights a significant vulnerability in the software supply chain, potentially impacting numerous applications and services that rely on these compromised libraries.

चेनड्रॉप मैलवेयर ने 1,300 से ज़्यादा npm पैकेज को संक्रमित किया

नाम के एक सेल्फ-प्रोपगेटिंग मैलवेयर ने Node Package Manager (npm) रजिस्ट्री पर 1,300 से ज़्यादा पैकेजों को हैक कर लिया है। इन संक्रमित पैकेजों को हर महीने 2 अरब से ज़्यादा बार डाउनलोड किया गया है। Keyv और Cacheable जैसे पॉपुलर पैकेज भी इसकी चपेट में आए हैं। यह बड़ा हमला सॉफ्टवेयर सप्लाई चेन में एक बड़ी कमजोरी दिखाता है, जिससे इन लाइब्रेरी पर निर्भर कई ऐप्स और सेवाएं प्रभावित हो सकती हैं।