CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

'ChainDrop' worm compromises hundreds of popular npm packages

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6651

As cited

Copy frozen at (site build).

threat intel

'ChainDrop' worm compromises hundreds of popular npm packages

On August 4, 2026, hundreds of popular npm packages including 'keyv' were compromised to distribute malware through what appears to be a supply chain attack. The compromise suggests attackers gained access to multiple package accounts or the npm registry itself, allowing injection of malicious code into trusted dependencies.

Why it matters: Developers using affected npm packages face immediate risk of deploying malware into production environments; teams should audit their dependency trees for compromised versions and implement supply chain verification controls.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary