#ChainDrop
If anyone happens to work at a shop with a lot of JS/TS, there's a new funky credential stealer worm called ChainDrop that's hit like 400+ NPM packages.

I built a scanner to identify possibly affected projects: github.com/mlowdi/chain...
GitHub - mlowdi/chaindrop-scan: Scanner to identify projects possibly affected by ChainDrop
Scanner to identify projects possibly affected by ChainDrop - mlowdi/chaindrop-scan
github.com
August 6, 2026 at 11:43 AM
✨ Dopo axios e il worm ChainDrop, Drop propone una sandbox per Linux in cui npm install e gli agenti AI girano senza vedere chiavi SSH, token e credenziali cloud 👇
gomoot.com/drop-la-sand...

#drop #gvisor #kernel #Linux #opensource #sandbox
September 23, 2026 at 4:53 PM
ChainDrop worm crawls into npm supply chain, evades standard defenses
ChainDrop worm crawls into npm supply chain, evades standard defenses
Shai-Hulud variant poisons 444 packages, spreads via tarballs and dev-tool hooks
www.theregister.com
August 15, 2026 at 10:33 AM
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.
Massive ChainDrop npm supply-chain attack infects hundreds of packages
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.
www.bleepingcomputer.com
August 4, 2026 at 3:24 PM
ChainDrop worm crawls into npm supply chain, evades standard defenses
ChainDrop worm crawls into npm supply chain, evades standard defenses
Shai-Hulud variant poisons 444 packages, spreads via tarballs and dev-tool hooks
www.theregister.com
August 15, 2026 at 10:52 AM
Bis auf 5x chaindrop nix passiert tatsächlich, meine Hände sind nur komplett offen weil ich mich weigere Handschuhe zu tragen 😅
April 13, 2025 at 2:29 PM
🚨 ChainDrop poisons 1.300 npm packages

The worm steals credentials and self-spreads through trusted releases.
🔗 read more: www.bleepingcomputer...

#ransomNews #cybersecurity
Massive ChainDrop npm supply-chain attack infects hundreds of packages
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.
www.bleepingcomputer.com
August 7, 2026 at 11:37 AM
ChainDrop, variant del cuc npm Shai-Hulud: 444 paquets enverinats (~2.000M baixades/mes).
Es propaga per tarballs i hooks de VS Code/Claude Code.
Només cal obrir una branca infectada per ser-ne victima.

www.theregister.com/security/202...

Si en vols saber més: ls-lisa.com/enverinament...
ChainDrop worm crawls into npm supply chain, evades standard defenses
Shai-Hulud variant poisons 444 packages, spreads via tarballs and dev-tool hooks
www.theregister.com
August 16, 2026 at 9:39 AM
ChainDrop Solucanı npm Tedarik Zincirini Vurdu: Standart Savunmaları Nasıl Atlatıyor?
ChainDrop Solucanı npm Tedarik Zincirini Vurdu: Standart Savunmaları Nasıl Atlatıyor?
Yazılım dünyasının kalbi olan npm ekosistemi, sofistike bir siber saldırıyla sarsıldı. Shai-Hulud zararlı yazılımının yeni bir varyantı olan ChainDrop, popül…
teknovizor.com
August 15, 2026 at 11:25 AM
Researchers: ChainDrop, a Shai-Hulud-based worm, compromised 1,300+ npm packages, including Keyv and Cacheable, with a combined 2B monthly downloads (Bill Toulas/BleepingComputer)

Main Link | Techmeme Permalink
August 4, 2026 at 3:45 PM
ChainDrop worm crawls into npm supply chain, evades standard defenses

This article frames the ongoing security landscape as a series of disparate, high-stakes incidents rather than pointing toward an emerging, unified systemic risk from autonomous AI agents. While specific attacks are alarming,…
arc-codex.com
August 15, 2026 at 9:44 PM
Microsoft has published an in-depth technical analysis of the supply chain attack known as "ChainDrop" affecting hundreds of packages and delivering a self-propagating credential-stealing worm. Read our blog for mitigation, detection, and hunting guidance: msft.it/63322aDU0s
ChainDrop supply chain compromise: Anatomy of a self-propagating worm | Microsoft Security Blog
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, affected environments, and practical guidance for detection, hunting, and remediation.
msft.it
August 4, 2026 at 11:53 PM
If you are developing stuff in JavaScript, be aware of ChainDrop, the new npm self-replicating worm. It has infected several very popular packages, so you might check whether or not you have been infected.

www.stepsecurity.io/blog/chaindr...
ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2 - StepSecurity
ChainDrop npm worm: 444 packages and 2,212 versions poisoned, starting with keyv@6.0.0. Payload analysis, affected package list, IOCs, and remediation steps.
www.stepsecurity.io
August 4, 2026 at 8:54 PM
-Websites of Russian banks break due to CA revokations
-OpenAI disrupts Cambodian scam center
-SMS blaster detained in Hong Kong
-Malware moves to D2IP connections
-FBI issues new swatting alert
-AI is prevalent in African cybercrime
-Malicious links found in AI summaries
-ChainDrop worm hits npm
August 5, 2026 at 9:02 AM
Oh good, the sandworm is back and abusing Claude code. Just not in the way you think… (medium.com/governed-at-...
The ChainDrop npm Worm (August 2026): How 444 Packages Were Compromised Without a Single npm…
The attacker skipped the step everyone spent three years watching.
medium.com
August 16, 2026 at 10:37 PM
🚨 *ChainDrop: a self-propagating npm worm has compromised more than 400 packages.**

The campaign shows how attackers can abuse trusted open-source dependencies to steal developer credentials and spread through the software supply chain.

🔗 netbe.pl/chaindrop-ho...

#Cybersecurity #npm #Malware
ChainDrop: How a Self-Propagating npm Worm Compromised More Than 400 Packages |
ChainDrop: How a Self-Propagating npm Worm Compromised More Than 400 Packages
netbe.pl
August 22, 2026 at 11:55 AM
ChainDrop, a new npm worm, has already compromised 435+ packages by exploiting stolen maintainer credentials. If you use npm, assume your environment may be at risk.

https://lwn.net/Articles/1087108/

#opensource #Linux
August 6, 2026 at 7:30 PM
Massive ChainDrop npm supply-chain attack infects hundreds of packages
Massive ChainDrop npm supply-chain attack infects hundreds of packages
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. [...]
www.bleepingcomputer.com
August 4, 2026 at 3:47 PM
August 17, 2026 at 6:40 AM
ChainDrop: Inside a Self-Propagating npm Worm https://packetstorm.news/news/view/42678 #news
August 7, 2026 at 5:59 PM