Chaindrop: Shai-Hulud, here we go again!

Microsoft published a detailed analysis of the new ChainDrop supply chain attack affecting NPM packages and adopting self-replicating, worm behaviour, similar to Shai-hulud:

The malware typically executes automatically through an npm preinstall lifecycle hook before package installation completes.

Once executed, the malware searches developer workstations and continuous integration and continuous delivery (CI/CD) environments for npm, GitHub, cloud, and infrastructure credentials. It uses recovered identities to authenticate to npm, GitHub, Amazon Web Services (AWS), Kubernetes, and HashiCorp Vault, enabling it to enumerate packages, repositories, workflow secrets, cloud parameters, and secret-store values. Collected data is encrypted and transmitted through an attacker-controlled HTTPS endpoint, with GitHub repositories serving as a fallback exfiltration channel.

The self-replication part leverages the very permissive configuration system of tools like Visual Studio Code or Claude Code to re-inject the payload to other environments on top of contaminating available NPM repositories:

The payload’s most significant capability is automated propagation. After obtaining an npm publishing token, it enumerates packages available to the compromised identity, downloads their latest tarballs, inserts the malware and setup loader, adds a preinstall hook, increments the patch version, and republishes the modified packages. The malware can also use stolen GitHub credentials to inject Claude and Visual Studio Code configuration files into repositories, establishing persistence and creating an additional developer-to-developer infection path.

As often, an easy way to “vaccinate” your endpoint is to work in Cyrillic:

During preflight, the payload checks the environment, exits on Russian-language system

What can we do against it? Whitelisting NPM packages in your corporate environment doesn't suffice here, as the malware is contained in legitimate package whose publisher credentials have been compromised. We then have two options left.

First, hoping the EDR catches it before it executes. In some organizations, developers are fighting tooth and nail against on-access scans in development folders as it can severely impact compilation time. This is especially true for ecosystems generating thousands of small files like Java and JavaScript. Better check the file path where ChainDrop land would have been covered.

In addition, you can implement mandatory cooldown between the release of a new package and its installation by NPM, hoping that the malware would get caught in between. The main issue with this approach is its tradeoffs. Sure, the longer you wait, the more likely the supply chain attack will be detected and contained by the time you install it. But cooldown is indiscriminate, it will also delay any important security patches coming from legitimate new versions. We are in a trend where the time between public announcement and security fixes and exploitation of the underlying vulnerability in the wild is getting exponentially shorter. How long are you OK to wait?

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论