安全客August 11, 2026🇨🇳Translated from Chinese

ChainDrop Malware Infects Over 1,300 npm Packages in Record Supply Chain Poisoning Campaign

ChainDrop malware has infected more than 1,300 npm packages with a combined monthly download volume of 2 billion, marking one of the largest supply chain poisoning incidents recorded to date. If you updated an npm dependency in the past week, your development credentials may already have been exfiltrated to attacker infrastructure.

The attack begins when an infected package executes inside a developer environment. It first reads the local .npmrc file to extract npm authentication tokens. Next, it scans for SSH keys and Git configuration files to obtain access to code repositories. Finally, the malware uses the stolen npm token to publish malicious updates to any other packages owned by the same account, creating a self-replicating infection chain.

Simultaneously, the Open VSX marketplace removed 77 malicious extensions that used a “twin” naming strategy to impersonate legitimate developer tools. These extensions collected hostnames, repository metadata, CI environment variables, and credential files. Their combined download count exceeded one million.

A third vector, dubbed HalluSquatting, targets AI coding assistants. Attackers monitor suggestions from tools such as GitHub Copilot, Cursor, and Claude Code for non-existent package names. Once a frequently hallucinated name is identified, the attacker registers the package with malicious code. Developers who accept the AI-generated import statement unknowingly install the backdoor.

The three incidents underscore the expanding attack surface of modern software supply chains. With more than three million packages in the npm ecosystem and thousands of new versions published daily, traditional “trust your direct dependencies” approaches are no longer sufficient. Defenses must now cover lockfiles, token scoping, and verification of AI-suggested packages.

Recommended mitigations include pinning all direct and transitive dependencies with integrity hashes, issuing npm tokens with publish rights only when necessary, and manually checking any package name suggested by an AI assistant for recent registration dates or missing maintainer information.

Related articles

HabrSupply Chain & Open Source

redb 3.7.2 Released with Custom gRPC Protocol, Dependency Vulnerability Fixes and .NET 10 Migration

The redb ecosystem released versions 3.7.0, 3.7.1 and 3.7.2 in quick succession after 3.7.0 was withdrawn due to high-severity vulnerabilities in its .NET 9 build artifacts. NuGet audit detected issues only on full rebuilds, leading to updates for SSH.NET, Microsoft.Data.Sqlite, System.Security.Cryptography.Xml and Microsoft.Bcl.Memory across redb.Route, redb.Core, redb.Export and redb.Identity. The release introduces a native GrpcWire implementation that registers individual gRPC methods as routes on a shared Kestrel host, supports bidirectional streaming, real gRPC status codes and mTLS with pinned client certificates. redb.Route also gained a dedicated SOAP connector, Control Bus messaging for route lifecycle management and a corrected Claim Check pattern. File transports received critical fixes that prevent silent data loss when readLock and idempotency options are combined. All libraries now target net8.0;net9.0;net10.0 while host applications require .NET 10, aligning with Microsoft’s shortened support timeline for .NET 8 and 9.

安全客Supply Chain & Open Source

Poisoned Rust Crates Execute Malware at Build Time: 245 Million Downloads Hit in Supply-Chain Attack

Three widely used Rust crates on crates.io were poisoned on August 20 with malicious versions that execute automatically during cargo build. The attack leveraged a typosquatted proc-macro1 dependency containing a build script that downloads payloads and establishes persistence. arrayref alone has accumulated 245 million downloads and is pulled automatically through caret ranges in many dependency trees. Attack infrastructure overlaps with prior campaigns attributed to Sapphire Sleet and MIDNIGHT NEPTUNE. Rust security teams yanked the malicious releases within 86-107 minutes, but the incident highlights missing publish-age controls and weak maintainer-account protections in the Cargo ecosystem.

HabrSupply Chain & Open Source

PyPI Explores Prefix Reservation for Organizations Under PEP 752 to Prevent Name Squatting

PEP 752 proposes reserving package name prefixes for organizations on PyPI, allowing control over entire families of related package names rather than individual entries. The change addresses dependency confusion and name squatting risks where attackers register packages with familiar prefixes like google-cloud- or opentelemetry- to exploit user trust. Analysis of over 800,000 PyPI projects by CodeScoring shows that prefixes are rarely controlled by a single owner, with ecosystems like aws- managed by hundreds of accounts. The proposal introduces implicit namespaces and new metadata for clients and proxies while preserving the flat namespace model familiar to Python developers. PEP 755 will define the governance process for granting prefix rights, limiting applications to organizations and requiring clear justification. Existing packages receive backward compatibility exceptions, and the mechanism does not transfer across repositories.

HabrSupply Chain & Open Source

Suspicious Certificate Issuer Detected in MAX Messenger Windows Update Package

A detailed observation from a security researcher highlights an unexpected change in the code signing certificate for the MAX messenger desktop client on Windows. The August update package was signed by an individual named Konstantin Syomochkin instead of the usual Communication Platform LLC. This discrepancy raised concerns about potential supply chain interference linked to recent EU sanctions against the developer. The certificate was issued shortly after sanctions and belongs to a person based in Astana, Kazakhstan, with limited public ties to the VK team. Official MSI installers downloaded directly from the MAX website remain signed by the company, while the client-triggered update differs in both version and signer. The researcher recommends that VK verify the download chain through Mail.ru trackers to rule out tampering. Installation of the update was declined pending further clarification.