LIVE FEED
DPRK npm Supply Chain Worm Uses Web3 C2 to Steal Cloud Keys

DPRK npm Supply Chain Worm Uses Web3 C2 to Steal Cloud Keys

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 6.5 Palo Alto Unit 42

North Korea-affiliated threat actors have escalated software supply chain attacks by embedding a self-propagating npm worm, ChainDrop, across over 400 packages to harvest ephemeral cloud IAM credentials and CI/CD tokens. The campaign introduces Web3-based command-and-control via EtherHiding smart contracts, enabling attackers to dynamically update exfiltration endpoints across entire botnets without altering malware binaries. Targeted projects include AI frameworks such as Mastra AI, raising direct concerns for AI development pipelines and their cloud infrastructure.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.