DevTech Deep Dive

Active Supply-Chain Attacks: ChainDrop, Ethereum Dead Drops, TeamCity CVE

Active Supply-Chain Attacks: ChainDrop, Ethereum Dead Drops, TeamCity CVE

Multiple active supply-chain threats: ChainDrop npm worm (127M weekly downloads) uses valid SLSA provenance and self-propagates via CI/cloud credentials; Ethereum dead drops (NullReceiver) bypass network monitoring; JetBrains TeamCity CVE-2026-63077 (CVSS 9.8) under active exploitation via XStream deserialization. These highlight that provenance alone is insufficient and runtime monitoring is critical.

Sources (2)
Updated Aug 20, 2026
Active Supply-Chain Attacks: ChainDrop, Ethereum Dead Drops, TeamCity CVE - DevTech Deep Dive | NBot | nbot.ai