ReversingLabs A.I CyberSecurity Scoring
ReversingLabs
Company Information
Website:http://www.reversinglabs.com
Employees number:332
Number of followers:51,786
NAICS:541514
Industry Type:Computer and Network Security
Homepage:reversinglabs.com
ReversingLabs Risk Score (AI oriented)
Between 700 and 749
ReversingLabsComputer and Network Security
Updated:
07/08/2026
07/08/2026
737/1000
Moderate
Ba
ReversingLabs Global Score (TPRM)
xxxx
ReversingLabsComputer and Network Security
Score locked

ReversingLabsModerate
Current Score
737Ba (MODERATE)
01000
2 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
754
Cyber Attack
07 Aug 2026 • ReversingLabs
cacheable-request, npm and keyv: ChainDrop Turns Stolen npm Tokens Into an Automated Package-Infection Engine
New npm Supply-Chain Worm 'ChainDrop' Automates Package Infections at Scale
737
CRITICAL-17
REVSOCNPM1786091119
New npm Supply-Chain Worm "ChainDrop" Automates Package Infections at Scale
A recently discovered npm supply-chain worm, dubbed ChainDrop, has compromised over 400 npm packages, including widely used projects like keyv and cacheable-request. The malware operates as an automated infection system, leveraging stolen developer credentials to propagate malicious code across the software supply chain.
### How ChainDrop Works
Once executed on a developer’s workstation or CI/CD pipeline, ChainDrop scans for sensitive credentials, including:
- npm and GitHub publishing tokens
- Cloud credentials, SSH keys, and Docker/Kubernetes configurations
- Terraform state files and environment variables
Using stolen npm credentials, the worm identifies all packages the compromised account can publish, then rebuilds, injects malicious code, increments version numbers, and republishes them all while maintaining the original functionality to avoid detection.
### Infection Mechanism & Evasion Tactics
ChainDrop modifies a package’s package.json file to include a preinstall hook that executes setup.mjs, a dropper script. The malware checks for the Bun JavaScript runtime, downloading it if absent, and uses it to run an obfuscated payload (mathinit.js). While Bun itself is not compromised, it is exploited as a portable execution environment.
Key evasion techniques include:
- Locale-based targeting: Exits on Russian-language systems, suggesting intentional geographic filtering.
- Memory scraping: A Python-based helper extracts GitHub Actions runner secrets and OpenID Connect tokens from live processes, capturing credentials that may never be written to disk.
- Persistence via developer tools: Creates malicious VS Code task files and Claude AI session hooks to re-execute the payload when projects are opened.
Researchers also identified dormant persistence mechanisms for macOS (LaunchAgent) and Linux (systemd user service), though these were not actively deployed in observed attacks.
### Impact & Scope
ChainDrop’s automated propagation poses a severe risk to:
- Developers (compromised workstations)
- CI/CD pipelines (injected build processes)
- Cloud environments (exposed credentials)
- Downstream users (infected dependencies)
The worm’s ability to republish legitimate packages with hidden malicious updates makes detection challenging, as infected packages continue to function normally.
### Indicators of Compromise (IOCs)
Security researchers have shared the following hashes for detection:
- Payloads:
- 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc (MathSymbol.js/mathinit.js)
- 54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668 (setup.mjs – first variant)
- fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb (setup.mjs – second variant)
- b27b82afa5f15512f3856e549fb83d873fd0049759a4b62ce64c8d7d4dc2c678
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
754
JUNE 2026
754
MAY 2026
754
APRIL 2026
753
MARCH 2026
753
FEBRUARY 2026
753
JANUARY 2026
753
DECEMBER 2025
753
NOVEMBER 2025
753
OCTOBER 2025
753
SEPTEMBER 2025
753
JUNE 2015
754
Cyber Attack
16 Jun 2015 • ReversingLabs
ReversingLabs
Expiration of the Cybersecurity Information Sharing Act (CISA 2015) and Its Impact on US Cyber Defenses
734
CRITICAL-20
REV3232932100225
The expiration of the Cybersecurity Information Sharing Act (CISA 2015) has left ReversingLabs—a cybersecurity firm heavily reliant on the law’s Automated Indicator Sharing Program (AIS)—vulnerable to legal liabilities when exchanging cyber threat intelligence. The lapse, driven by Congressional inaction during a government funding standoff, eliminates critical legal protections that previously encouraged voluntary threat data sharing among companies. Without these safeguards, ReversingLabs faces operational disruptions in maintaining its threat repositories, increasing exposure to software supply chain vulnerabilities and AI-enabled attacks.The company’s Chief Trust Officer, Saša Zdjelar, warned that the lapse creates a ‘chilling effect’ on threat intelligence collaboration, forcing firms to withhold data due to litigation risks. This weakens collective cyber defenses, granting adversaries a strategic advantage. Zdjelar also highlighted risks to AI security development, as legal uncertainty may restrict data-sharing essential for training AI-powered defense tools. The broader impact includes escalating costs of data breaches—already the highest globally in the U.S.—and potential long-term erosion of trust in cybersecurity partnerships, leaving critical infrastructure and enterprises more susceptible to sophisticated cyber threats.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for ReversingLabs ??
What was ReversingLabs's A.I Rankiteo Cyber Score in July 2026 ??
What was ReversingLabs's A.I Rankiteo Cyber Score in June 2026 ??
What was ReversingLabs's A.I Rankiteo Cyber Score in May 2026 ??
What was ReversingLabs's A.I Rankiteo Cyber Score in April 2026 ??
What was ReversingLabs's A.I Rankiteo Cyber Score in March 2026 ??
What was ReversingLabs's A.I Rankiteo Cyber Score in February 2026 ??
What was ReversingLabs's A.I Rankiteo Cyber Score in January 2026 ??
What was ReversingLabs's A.I Rankiteo Cyber Score in December 2025 ??
What was ReversingLabs's A.I Rankiteo Cyber Score in November 2025 ??
What was ReversingLabs's A.I Rankiteo Cyber Score in October 2025 ??
What was ReversingLabs's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on ReversingLabs's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with ReversingLabs ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view ReversingLabs's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?