ChainDrop Supply Chain Compromise: Anatomy of a Self-Propagating Worm
Microsoft Threat Intelligence has identified a large-scale supply chain attack impacting over 400 npm packages, including critical ecosystem dependencies like keyv and flat-cache. The campaign leverages a sophisticated, self-propagating worm variant dubbed ‘Mini Shai-Hulud’, which utilizes heavily obfuscated Bun-based JavaScript payloads. Attack Methodology The malware functions by exploiting npm preinstall…










