Skip to content

ChainDrop attack compromises over 1,300 npm packages with 2 billion monthly downloads

In brief: The self-propagating malware ChainDrop has compromised more than 1,300 npm packages with a combined total of around 2 billion monthly downloads.

A self-propagating malware named ChainDrop has infected more than 1,300 packages in the Node Package Manager (npm) registry. The affected packages together account for around 2 billion downloads per month.

According to BleepingComputer, malware operating under the name ChainDrop has spread autonomously within the npm registry, compromising more than 1,300 packages in the process. The affected package base totals roughly 2 billion downloads per month, underscoring the reach of the incident. The source does not provide specific technical details on the infection mechanism, the names of affected packages, or a CVE assignment.

For enterprise security leaders, the software supply chain via npm is a key attack vector, as JavaScript and Node.js projects often have deeply nested dependencies with dozens to hundreds of transitive packages. A self-propagating mechanism such as the one used by ChainDrop increases the risk that malicious code spreads unnoticed across multiple layers of the dependency chain into build pipelines and production environments, without requiring a targeted compromise of an individual maintainer account.

CISOs should have their Software Bill of Materials (SBOM) checked in the short term for the presence of affected npm packages, and use Software Composition Analysis (SCA) tools as well as lockfile audits to identify compromised versions. As the source does not include a list of affected packages or Indicators of Compromise (IOCs), it is advisable to closely monitor official npm security advisories and further reporting on ChainDrop over the coming days before finalizing countermeasures.


Source: www.bleepingcomputer.com · Published August 4, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: