<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Worm on CuraSec</title><link>https://curasec.metacog.co.kr/tags/worm/</link><description>Recent content in Worm on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 05 Aug 2026 13:01:27 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/worm/index.xml" rel="self" type="application/rss+xml"/><item><title>ChainDrop worm spread via 400+ malicious npm packages</title><link>https://curasec.metacog.co.kr/insights/2026-08-05-chaindrop-supply-chain-compromise-anatomy-of-a-self-propagat/</link><pubDate>Wed, 05 Aug 2026 13:01:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-05-chaindrop-supply-chain-compromise-anatomy-of-a-self-propagat/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> A self-propagating worm across 400+ npm packages directly threatens any JavaScript/Node.js dependency tree; audit all npm dependencies against the compromised package list in the Microsoft post, inspect CI/CD build logs for IOCs, and rotate any credentials present in affected build environments.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Microsoft&amp;rsquo;s write-up includes attack chain details and explicit detection and hunting guidance; run hunts for the described IOCs in pipeline and build-system logs and tune detections for the self-republishing propagation behavior since 2026-08-04.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> 400+ compromised npm packages is a systemic supply chain event comparable in breadth to prior ecosystem-wide incidents; this week confirm whether internal or third-party software uses affected packages and prepare a brief for leadership in case customers or the board surface questions.&lt;/li>
&lt;/ul></description></item></channel></rss>