← Back to Feed
Massive ChainDrop npm supply-chain attack infects hundreds of packages
August 4, 2026 · BleepingComputer · Severity: HIGH
The massive ChainDrop supply-chain attack has infected hundreds of npm packages with self-propagating malware. The malicious code compromised more than 1,300 packages, affecting over 2 billion monthly downloads.
Key Takeaways
- ChainDrop malware compromised over 1,300 npm packages.
- Affected packages have 2 billion monthly downloads.
- Attack is a large-scale supply chain threat.