ChainDrop supply chain compromise: Anatomy of a self-propagating worm
A self-propagating worm embedded in over 400 malicious npm packages spread through software supply chains by automatically republishing infected updates, stealing credentials along the way. Microsoft's security team has published a detailed breakdown of how the attack worked and how to detect or remediate it.
Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance