www.securityweek.com 8/5/2026, 9:01:42 AM · external

ChainDrop compromise hits NPM with 2,200 malicious packages

ChainDrop compromise hits NPM with 2,200 malicious packages
CyberSIXT Evidence Panel
Primary Source stepsecurity.io

A recent supply chain attack dubbed "ChainDrop" has compromised over 2,200 malicious versions of 440 packages in the NPM registry, with infected packages accumulating over 500 million weekly downloads. This campaign began with malware-laden packages in key namespaces, following the compromise of their maintainer's GitHub account. The malware steals sensitive information from developers' environments and uses this data to infect additional packages and repositories.

It includes functionalities to exfiltrate stolen credentials and republish modified packages, thereby broadening its reach. Survivors of the attack are advised to clean their systems, rotate compromised credentials, and audit their repositories for suspicious activities.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline