Threats Tagged 'developer credentials'
View all threats tagged with 'developer credentials'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'developer credentials'
Click on any threat for detailed analysis and mitigation recommendations
Inside a Self-Propagating npm Worm 0 ChainDrop is a self-propagating npm worm that infected over 400 widely used packages, including popular ones like keyv and cacheable-request. It steals sensitive developer credentials such as cloud credentials, npm and GitHub tokens, SSH keys, and extracts temporary credentials from GitHub Actions runner memory. The worm uses stolen npm publishing tokens to infect additional packages while preserving their legitimate functionality. Persistence is maintained through VS Code and Claude Code configurations. ChainDrop employs blockchain-based command-and-control (C2) infrastructure via Ethereum smart contracts, allowing silent reconfiguration of C2 without updating deployed instances. It uses multiple layers of obfuscation and encryption, exfiltrates data through encrypted channels, and publishes stolen tokens in public commit messages. Join the discussion | AlienVault OTX General | 08/07/2026, 10:27:00 UTC Added: 08/07/2026, 10:41:19 UTC |
Showing 1 to 1 of 1 result