06 Aug, 2026

Massive ChainDrop npm supply-chain attack infects hundreds of packages

Self-propagating malware named ‘ChainDrop’ has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. Infected packages include very popular ones such as Keyv and Cacheable, flat-cache and file-entry-cache, all caching utilities from the same maintainer.  The supply-chain attack started after the threat actor compromised the GitHub account of Keyv’s maintainer, and […]

4 mins read