www.stepsecurity.io 8/4/2026, 11:26:52 AM · external

ChainDrop npm worm hijacks packages using stolen maintainer login

ChainDrop npm worm hijacks packages using stolen maintainer login
CyberSIXT Evidence Panel Source marked as original reporting

THE ChainDrop npm worm is a self-propagating threat that has compromised numerous npm packages by using stolen maintainer credentials. This incident has led to the publication of malicious versions of dozens of packages, indicated by a spike in compromised releases in a short period. Key actions for users include checking package lockfiles for affected versions, assuming any installations are compromised, rotating credentials, and rolling back to safe versions. An active investigation is ongoing, with updates expected as more details come to light.

View full article

Article by CyberSIXT