ChainDrop: Inside a Self-Propagating npm Worm

2026-08-07T08:51:31Z581362e16724db07944fefd29ed4ab42de50b7c43ec7545567b23d886496e08a
AI-assisted cyberattacksCI/CD securityDLL sideloadingEthereum smart contract C2GitHub Actions secretsIoT botnetOT securitySiemens ROX IIVidar stealerWebAuthnXCSSETZimbra espionagecredential theftdirect-to-IP C2macOS malwarenpm supply-chain attackpasskeysransomwareself-propagating wormzero-day vulnerabilities

What happened

Unit 42 reporting covers major cybersecurity threats and research, including the ChainDrop self-propagating npm supply-chain worm stealing GitHub Actions secrets and using Ethereum smart contracts for C2, AI-assisted attacks and vulnerability discovery, passkey implementation weaknesses, XCSSET macOS malware, webmail espionage, Siemens ROX II OT zero-days, IoT botnets, ransomware, and information-stealing malware. The collection emphasizes supply-chain compromise, credential and secret theft, autonomous exploitation, persistence, and critical infrastructure risk.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
581362e16724db07944fefd29ed4ab42de50b7c43ec7545567b23d886496e08a
Enrichment time
2026-08-07T08:51:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.