Skip to content
supplychainattack.orgSupply chain attack incident catalog

Chaindrop supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. activecritical

    ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2

    ChainDrop is a self-propagating npm worm that publishes malicious versions of dozens of npm packages using stolen maintainer credentials. The worm harvests CI/CD credentials and uses an Ethereum-based dead-drop command-and-control mechanism.

    ChaindropnpmOtherCompromised packageMalicious maintainerAccount takeover