CYBERSECURITYTRACKER
TRACKING7,004 stories in this site build1,474 vulnerability news stories in this site build
Permanent story citation

Massive ChainDrop npm supply-chain attack infects hundreds of packages

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3827

As cited

Copy frozen at (site build).

threat intel

Massive ChainDrop npm supply-chain attack infects hundreds of packages

A self-propagating malware called ChainDrop has compromised more than 1,300 packages on the npm registry, affecting software with a combined 2 billion monthly downloads. The malware propagates by infecting packages and modifying their dependencies to spread further across the supply chain.

Why it matters: Development teams relying on npm packages face immediate exposure to malicious code that could be running in their builds and production systems; practitioners should audit their npm dependencies and lock file histories to identify compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Massive ChainDrop npm supply-chain attack infects hundreds of packages

A self-propagating malware called ChainDrop has compromised more than 1,300 packages on the npm registry, affecting software with a combined 2 billion monthly downloads. The malware propagates by infecting packages and modifying their dependencies to spread further across the supply chain.

Why it matters: Development teams relying on npm packages face immediate exposure to malicious code that could be running in their builds and production systems; practitioners should audit their npm dependencies and lock file histories to identify compromise.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary