THE ChainDrop npm worm is a self-propagating threat that has compromised numerous npm packages by using stolen maintainer credentials. This incident has led to the publication of malicious versions of dozens of packages, indicated by a spike in compromised releases in a short period. Key actions for users include checking package lockfiles for affected versions, assuming any installations are compromised, rotating credentials, and rolling back to safe versions. An active investigation is ongoing, with updates expected as more details come to light.
ChainDrop npm worm hijacks packages using stolen maintainer login
CyberSIXT Evidence Panel
Source marked as original reporting
Article by CyberSIXT