#1
BleepingComputer
general
August 04, 2026 at 15:24 UTC
Massive ChainDrop npm supply-chain attack infects hundreds of packages
By Bill Toulas
AI Summary
Self-propagating 'ChainDrop' malware has compromised over 1,300 npm packages with a combined 2 billion monthly downloads, representing one of the largest npm supply-chain attacks on record. The malware auto-propagates across the registry, dramatically amplifying its reach and potential impact on Node.js-dependent software pipelines. Security teams should audit npm dependencies immediately and monitor for unexpected package version changes.
Relevance score: 92.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →