ChainDrop: Inside a Self-Propagating npm Worm
2026-08-07T08:51:31Z•581362e16724db07944fefd29ed4ab42de50b7c43ec7545567b23d886496e08a
AI-assisted cyberattacksCI/CD securityDLL sideloadingEthereum smart contract C2GitHub Actions secretsIoT botnetOT securitySiemens ROX IIVidar stealerWebAuthnXCSSETZimbra espionagecredential theftdirect-to-IP C2macOS malwarenpm supply-chain attackpasskeysransomwareself-propagating wormzero-day vulnerabilities
What happened
Unit 42 reporting covers major cybersecurity threats and research, including the ChainDrop self-propagating npm supply-chain worm stealing GitHub Actions secrets and using Ethereum smart contracts for C2, AI-assisted attacks and vulnerability discovery, passkey implementation weaknesses, XCSSET macOS malware, webmail espionage, Siemens ROX II OT zero-days, IoT botnets, ransomware, and information-stealing malware. The collection emphasizes supply-chain compromise, credential and secret theft, autonomous exploitation, persistence, and critical infrastructure risk.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 581362e16724db07944fefd29ed4ab42de50b7c43ec7545567b23d886496e08a
- Enrichment time
- 2026-08-07T08:51:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.