Summary
A new ChainDrop worm, a variant of Shai-Hulud, has infected over 1,300 npm packages, including Keyv and Cacheable, by compromising GitHub accounts. This infostealer exfiltrates developer and cloud credentials to a public GitHub repository, prompting a recommendation for affected systems to be treated as compromised.