<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>ChainDrop on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/chaindrop/</link><description>Recent content in ChainDrop on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Wed, 05 Aug 2026 12:24:22 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/chaindrop/index.xml" rel="self" type="application/rss+xml"/><item><title>ChainDrop Worm Steals Your Keys the Moment You Run npm Install</title><link>https://hackingpassion.com/chaindrop-npm-worm-keyv/</link><pubDate>Wed, 05 Aug 2026 12:24:22 +0200</pubDate><guid>https://hackingpassion.com/chaindrop-npm-worm-keyv/</guid><description>&lt;p>A worm dumped 1,300 stashes of stolen developer keys into public GitHub repos in a day. You ran &lt;code>npm install&lt;/code>. That was all. The poison sat in a library npm hands out &lt;strong>153 million times a week&lt;/strong>. 🧐&lt;/p>
&lt;p>There was no phishing email and nothing suspicious to download. You typed &lt;code>npm install&lt;/code>, or your build server did it at three in the morning while you slept, and attacker code ran before the install had finished.&lt;/p></description></item></channel></rss>