ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Open Source

ChainDrop npm malware spreads through 1,300+ packages with broad installs

Source headline: Massive ChainDrop npm supply-chain attack infects hundreds of packages

Threat level Critical
Signal strength 85/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

A self-propagating malware called ChainDrop has been found in more than 1,300 npm packages. The affected packages together account for roughly 2 billion monthly downloads. ChainDrop can deliver malicious code via the dependency install process, impacting any project that pulls the compromised modules. The large number of packages increases the likelihood that many downstream applications include the infected dependencies. npm users and developers should review dependency trees, update packages to known-good versions, and monitor for suspicious behavior in build and runtime environments.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#supply-chain #malware #npm #open-source #javascript #dependency-security
Original reporting BleepingComputer Massive ChainDrop npm supply-chain attack infects hundreds of packages
Open original source