DEV Community

relayshieldadmin
relayshieldadmin

Posted on

ChainDrop Had Valid Provenance. That Was Not Enough.

ChainDrop Had Valid Provenance. That Was Not Enough.

Attackers hijacked the GitHub account behind the keyv library to ship poisoned npm releases. The releases carried valid provenance, signed by GitHub Actions. Once installed, the payload raided machines for cloud and registry tokens, then spread worm-like to other maintainers. Four hundred packages. Two billion installs.

The signature was real. The signer was compromised.

Provenance answers the wrong question

Provenance tells you who signed a package. It does not tell you whether the signer should be trusted right now. When a maintainer's GitHub account is hijacked, every subsequent release carries a valid signature from a compromised source. The cryptography is working exactly as designed. The trust assumption underneath it is broken.

This is not a new pattern. It is the same mechanics behind every supply-chain attack: the signing infrastructure is intact, the human behind it is not.

Two places to stop it

Before the commit: rsscan.

ChainDrop's payload steals cloud tokens, registry tokens, and GitHub PATs from infected machines, then uses them to spread. If the worm tries to exfiltrate those tokens through a git commit, a pre-commit hook that scans for credentials stops it cold.

RSSCAN is our free, local pre-commit hook. It detects 49 credential patterns (AWS keys, GitHub PATs, Stripe secrets, private keys, LLM provider keys) and blocks the commit before the secret enters git history. No account, no API key, no network call. Your source code never leaves the machine.

A CI check only sees the secret after push. By then it is in history and has to be rotated. The pre-commit hook is the point.

After the publish: package reputation.

For consumers of npm packages, the question is different: is this version safe to install? Valid provenance does not answer it. Threat intelligence does.

A package reputation check compares the package name and version against known-malicious indicators: versions published from hijacked accounts, packages with sudden maintainer changes, typosquat variants. The signature says who published it. The reputation check says whether you should trust them today.

The trust layer is intelligence, not signatures

ChainDrop validates a thesis we have been building on: in a supply-chain attack, the cryptography is the last thing to fail. The maintainer's account, the CI runner, the publishing token, those go first.

The defense is not a better signature. It is knowing, at install time and at commit time, whether the source is compromised.

Signatures prove origin. Intelligence proves trustworthiness. You need both.


RSSCAN is free and open source: github.com/relayshield/rsscan. For API-based supply-chain screening, see api.relayshield.net/developers.

Top comments (1)

Collapse
 
indiainfranotes profile image
IndiaInfraNotes •

A valid signature only proves the GitHub Action that signed it was still the right one. If the maintainer account is already compromised, the provenance chain is honest and the trust is not. The missing check is whether the signer is still the expected actor, not whether the signature bytes match. Who verifies the signer is still the original maintainer?

iin1007h01