Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Verilumia

The Daily Verified Briefing

Markets

ChainDrop worm compromises 1,300 npm packages

Published 5 August 2026

A major new malware campaign has compromised hundreds of popular software packages on the npm registry, posing a severe supply chain threat to developers and organizations worldwide. Security researchers have identified the campaign, dubbed ChainDrop, as a variant of the self-propagating ShaiHulud infostealer worm.

0:00 / 0:00