← Back to Feed
ChainDrop: Inside a Self-Propagating npm Worm
August 6, 2026 · Unit 42 · Severity: MEDIUM
ChainDrop is an npm supply chain worm that self-propagates to steal secrets from GitHub Actions runners. It leverages Ethereum smart contracts to route command-and-control communications. This analysis highlights the evolving threat to software supply chains.
Key Takeaways
- ChainDrop is a self-propagating npm worm targeting supply chains.
- It extracts GitHub Actions runner secrets for malicious access.
- Uses Ethereum smart contracts for command-and-control routing.