← Back to feed
general GBHackers

ChainDrop Publishes Initial Malware Without Stealing a Long-Lived npm Token

GBHackers

The ChainDrop campaign has exposed a gap in modern software supply-chain defenses: malware no longer needs a durable npm publishing token or even an npm inst...

Read the full story GBHackers →

Related Coverage

general Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes Help Net Security · Sep 23 general Arista Urges Immediate Patching of Exploited VCO Zero-Day SecurityWeek · Sep 23 general Claude Opus 5.5 cuts costs and adds safeguards for autonomous AI Help Net Security · Sep 23