← Back to Feed

Massive ChainDrop npm supply-chain attack infects hundreds of packages

August 4, 2026 · BleepingComputer · Severity: HIGH

The massive ChainDrop supply-chain attack has infected hundreds of npm packages with self-propagating malware. The malicious code compromised more than 1,300 packages, affecting over 2 billion monthly downloads.

Key Takeaways

  • ChainDrop malware compromised over 1,300 npm packages.
  • Affected packages have 2 billion monthly downloads.
  • Attack is a large-scale supply chain threat.
☕ Buy a Coffee