Palo Alto Networks Unit 42 research shows that ChainDrop, a self-propagating npm supply chain worm, extracts GitHub Actions runner memory secrets, targets specific repositories, and alters C2 domains with one Ethereum transaction.
Public source
Publisher name
Public post
ChainDrop, a self-propagating npm supply chain worm, infected hundreds of popular packages. Palo Alto Networks Unit 42 research shows it extracts GitHub Actions runner m…
Company
Palo Alto Networks Unit 42
Unit 42 Threat Intelligence & Incident Response. Intelligence Driven. Response Ready.
- Industry
- Computer and Network Security
- Location
- SANTA CLARA, US
- Company size
- 501–1,000 employees
About Palo Alto Networks Unit 42
Palo Alto Networks Unit 42 brings together world-renowned threat researchers with an elite team of incident responders and security consultants to create an intelligence-driven, response-ready organization passionate about helping customers more proactively manage cyber risk. With a deeply rooted reputation for delivering world-class threat intelligence, Unit 42 provides industry-leading incident response and cyber risk management services to security leaders around the globe.
See moreLatest activity
Latest activity from Palo Alto Networks Unit 42
23 signals
Research & Knowledge
Palo Alto Networks Unit 42 analyzed activity cluster CL-CRI-1163, where adversaries targeted the Brazilian financial sector by deploying custom SOCKS5 proxy tools alongside open directories filled with AI-generated python scripts.
Research & Knowledge
Palo Alto Networks Unit 42 analyzed activity cluster CL-CRI-1131, where adversaries integrated commercial AI models into operational workflows and used self-hosted NextChat instances to troubleshoot data collection errors in real time.
Products & Services
Palo Alto Networks Unit 42 reported that an unpatched, unauthenticated RCE zero-day vulnerability named 'StyleSmuggler' is being exploited to compromise e-commerce sites running Magento Open Source and Adobe Commerce.
Discover more
Similar signals
Similar public activity from other companies.
Research & Knowledge
Palo Alto Networks
Palo Alto Networks Unit 42 analyzed Aeternum, a newly discovered C++ botnet loader that shifts its command-and-control infrastructure to the public Polygon blockchain.
Research & Knowledge
EclecticIQ
EclecticIQ published research showing that supply-chain campaigns often resurface under different names across ecosystems and weeks apart, making manual tracking difficult.
Research & Knowledge
Mend.io
Mend.io security research team analyzed the Mini Shai-Hulud attack on openapi-react-query-codegen, exposing how compromised npm dependencies silently steal developer secrets during routine workflows.
Research & Knowledge
Lineaje
Lineaje published a research paper titled AI TAR VIDEO: An AI coding agent turned a routine repository read into a secret exfiltration pipeline — no jailbreak required, just the privilege it already had.
Research & Knowledge
Carbon Black