ChainDrop npm malware spreads through 1,300+ packages with broad installs
Source headline: Massive ChainDrop npm supply-chain attack infects hundreds of packages
Intelligence Summary
A self-propagating malware called ChainDrop has been found in more than 1,300 npm packages. The affected packages together account for roughly 2 billion monthly downloads. ChainDrop can deliver malicious code via the dependency install process, impacting any project that pulls the compromised modules. The large number of packages increases the likelihood that many downstream applications include the infected dependencies. npm users and developers should review dependency trees, update packages to known-good versions, and monitor for suspicious behavior in build and runtime environments.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.