Skip to content

Security1 publisherNot yet confirmed elsewhere3 min readPublished Updated

Reading OIDC tokens out of runner memory: ChainDrop and the poisoned build

Unit 42 says a worm hidden in more than 400 npm packages read GitHub Actions runner memory for temporary OIDC tokens. An SBOM generated at the end of the build would not have seen any of it.

The Watch · Security desk

How we use AISend a correction

What happened

  • Unit 42 reports the past 12 to 18 months changed the scale and speed of supply chain attacks, with developer tools and code the target rather than finished software.
  • Its research names the ChainDrop npm worm, which infected more than 400 packages including the widely used keyv and cacheable-request.
  • ChainDrop's preinstall script downloaded the legitimate Bun runtime to launch a 727 KB obfuscated payload in the background.
  • Unit 42 places ChainDrop alongside the XZ Utils backdoor (CVE-2024-3094), the Axios account hijack and the Shai-Hulud npm worm.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint The artifact most programmes point at, an SBOM produced at the end of a build, cannot answer whether malware ran during that build, so it is no evidence either way about this class of compromise.
  • exposure Because install scripts and editor extensions run unsandboxed with the developer's own permissions, the laptop holding cloud tokens is inside the blast radius of any routine dependency update.
  • precedent Since the republished packages kept working normally, teams cannot treat user-visible breakage as the alarm; detection has to come from watching the pipeline, not the bug tracker.
  • decision Rolling back package versions and rotating CI credentials no longer closes the incident, which forces a call on whether developer machines get reimaged.

Where ChainDrop went looking for secrets is the detail worth keeping. Alongside a broad sweep for credentials sitting on developer disks, a hidden Python script read live process memory on GitHub Actions runners to lift temporary OpenID Connect tokens and secrets [1]. Federated, short-lived credentials are the standard answer to long-lived keys pasted into CI settings. Reading them out of a running job makes the expiry beside the point, because the worm spends them at once: Unit 42 says it used the stolen npm and GitHub tokens to republish further packages [c9a].

The persistence is the other half of the design. According to Unit 42, ChainDrop wrote cross-linked hooks into developer tooling, including VS Code and Claude Code, and ran its command and control dynamically through Ethereum blockchain transactions [4]. Two things follow from that pairing. There is no domain to seize or sinkhole, and the surviving foothold sits on a laptop rather than in a registry or a runner [13]. An incident closed when the bad versions are unpublished has been closed in the wrong place.

The scale argument underneath this is arithmetic rather than atmosphere. Unit 42 puts open source at 80 to 90 percent of modern codebases and says the surface now includes developer laptops, CI/CD and cloud infrastructure [16]. It also contrasts a project of ten years ago depending on a few dozen external libraries with a simple application today pulling thousands of indirect dependencies [17]. Read at the low end of both figures, that is roughly a 55-fold increase in third-party code arriving per build [19]. Every one of those arrivals can carry a preinstall hook that fires silently the moment someone runs npm install, and ChainDrop's fired at three targets: build server memory, local editor config such as tasks.json, and rogue repositories used to spread further [5].

The reason install-time code works so well is a missing boundary rather than a clever exploit. A browser confines a website to a sandbox; setup scripts and editor extensions have no such walls and inherit the developer's own permissions, free to read files and run commands [7]. That permission grant is handed out constantly, across npm, pip, cargo, go and maven installs, by people also running somewhere between 10 and 30 IDE extensions [18]. Unit 42's summary is that attackers are aiming at CI/CD pipelines and developer environments to hijack software before it reaches production [15], and the ChainDrop mechanics make that concrete.

One caveat on the whole picture: this is a single vendor's research, and the package counts, the payload size and the memory-reading technique are Unit 42's own findings [11]. Nobody else in the reporting has confirmed them.

What to watch

  • Whether npm or other registries move to restrict or disable install-time scripts by default, which is the single hook ChainDrop depended on.
  • Whether GitHub hardens Actions runners against in-process reads of short-lived OIDC tokens, or treats memory access on the runner as in-scope for the platform.
  • Whether researchers outside Unit 42 publish their own package lists and payload analysis for ChainDrop, since the 400-plus figure is currently single-sourced.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption62
Hype gap+18
Incentives80
Confidence52
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    In ChainDrop's theft stage, a hidden Python script directly read live process memory from GitHub Actions runners to steal temporary OpenID Connect (OIDC) tokens and secrets, alongside a broad sweep for local developer credentials.

  2. [2]

    ChainDrop used stolen npm and GitHub tokens to self-propagate, silently infecting and republishing additional packages.

  3. [3]

    ChainDrop left the legitimate functionality of the packages it republished perfectly intact so that developers do not notice.

Sources

1 independent publisher whose own reporting we read for this story.

  1. unit42.paloaltonetworks.com

    1 article · August 21, 2026

    Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories