Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'ci/cd compromise'

View all threats tagged with 'ci/cd compromise'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: ci/cd compromise

Threats Tagged 'ci/cd compromise'

Click on any threat for detailed analysis and mitigation recommendations

Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack
0

ChainDrop is a self-propagating worm that has compromised over 400 npm packages in a major software supply chain attack. It exploits stolen npm publishing credentials to modify and republish legitimate software releases automatically. The malware targets developer workstations and CI/CD environments, stealing credentials from multiple platforms including npm, GitHub, AWS, Kubernetes, and HashiCorp Vault. It uses preinstall lifecycle scripts for automatic execution and persists by modifying repository configurations and abusing GitHub Actions OIDC workflows. After stealing credentials, ChainDrop autonomously propagates by inserting malicious payloads into packages and republishing them with incremented versions, enabling widespread compromise of the software ecosystem.

Join the discussion
Supply Chain Compromise Affecting keyv and cacheable npm Packages
0

An active supply chain attack has compromised the keyv and cacheable npm packages, affecting tens of millions of weekly downloads. The attack began on August 4, 2026, when the maintainer account Jaredwray was compromised, enabling attackers to publish malicious code across multiple packages. The malware deploys through a preinstall hook that downloads a Bun runtime and executes obfuscated payloads designed to harvest cloud credentials from AWS, GCP, Azure, HashiCorp Vault, Kubernetes, GitHub Actions, and npm tokens. The threat exhibits worm-like behavior by using stolen npm tokens to republish trojanized versions of additional packages beyond the original namespaces. Stolen credentials are exfiltrated to attacker-controlled GitHub repositories via DNS-resolved destinations, with persistence mechanisms planted in developer environments through .claude and .vscode hooks.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: ci/cd compromise
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses