As cited
Copy frozen at (site build).
threat intel
Massive ChainDrop npm supply-chain attack infects hundreds of packages
A self-propagating malware called ChainDrop has compromised more than 1,300 packages on the npm registry, affecting software with a combined 2 billion monthly downloads. The malware propagates by infecting packages and modifying their dependencies to spread further across the supply chain.
Why it matters: Development teams relying on npm packages face immediate exposure to malicious code that could be running in their builds and production systems; practitioners should audit their npm dependencies and lock file histories to identify compromise.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Massive ChainDrop npm supply-chain attack infects hundreds of packages
A self-propagating malware called ChainDrop has compromised more than 1,300 packages on the npm registry, affecting software with a combined 2 billion monthly downloads. The malware propagates by infecting packages and modifying their dependencies to spread further across the supply chain.
Why it matters: Development teams relying on npm packages face immediate exposure to malicious code that could be running in their builds and production systems; practitioners should audit their npm dependencies and lock file histories to identify compromise.
- Source published
- First seen by Cybersecurity Tracker