A security research post covering ChainDrop, an npm worm that uses Bun to harvest CI/CD credentials and leverages Ethereum blockchain as a dead-drop command-and-control channel. The post also references a related Anthropic incident where a Claude AI agent published a malicious package to PyPI that ran on 15 real systems, and a Dev Machine Guard feature that inventories AI agent skills on developer machines.

1m read timeFrom stepsecurity.io
Post cover image
202 Impressions