Skip to content
supplychainattack.orgSupply chain attack incident catalog
activecritical

Massive ChainDrop npm supply-chain attack infects hundreds of packages

Self-propagating malware named 'ChainDrop' has compromised more than 1,300 npm packages with a combined 2 billion monthly downloads. The attack represents a large-scale supply chain compromise affecting the Node Package Manager ecosystem.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
1,300+ npm packages with 2 billion combined monthly downloads
Ecosystems
Attack vectors
Threat actor
Affected entities
  • npm packages (multiple)Self-propagating malware 'ChainDrop' compromised 1,300+ packages

A self-propagating malware campaign named 'ChainDrop' has compromised over 1,300 packages in the npm registry. The affected packages collectively receive approximately 2 billion monthly downloads, indicating widespread potential exposure.

The malware's self-propagating nature suggests it may be designed to spread across package dependencies, potentially infecting additional packages and downstream consumers. The scale of the compromise—affecting more than 1,300 packages—indicates a significant supply chain attack with broad reach across the Node.js ecosystem.

As of the report date (August 4, 2026), the attack appears to be ongoing, with the malware actively compromising packages in the npm registry.

Remediation

  • Audit npm package dependencies for presence of ChainDrop malware
  • Review package.json and lock files for unexpected or suspicious package additions
  • Monitor npm package downloads and dependencies for anomalous behavior
  • Update to patched versions of affected packages once available
  • Consider implementing package integrity verification and signed package requirements
  • Review npm account security and enable two-factor authentication on npm accounts

Sources

  1. Massive ChainDrop npm supply-chain attack infects hundreds of packages · BleepingComputer

Cite this entry

"Massive ChainDrop npm supply-chain attack infects hundreds of packages." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 4, 2026; last updated August 4, 2026. https://supplychainattack.org/incident/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages-1pj9ly

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in sme-rko-finance-front-operations-feed-impl (npm)

    The npm package sme-rko-finance-front-operations-feed-impl contained malicious code that downloads and executes platform-specific binary payloads via Cloudflare Workers or DNS-based staging channels. The malware obfuscates child_process imports and executes on require(), making it active upon installation.

    npmCompromised package
  2. containedcritical

    Malicious code in sme-rko-finance-front-operations-overnight (npm)

    The npm package sme-rko-finance-front-operations-overnight contains malicious code that downloads and executes attacker-controlled binaries from Cloudflare Workers hosts on package require. The payload uses obfuscation techniques to evade static analysis and includes environment-based gating to reduce detection.

    npmCompromised package
  3. containedcritical

    Malicious code in sme-rko-finance-front-payment-registers-operations-domain (npm)

    The npm package sme-rko-finance-front-payment-registers-operations-domain contained malicious code that downloads and executes platform-specific binaries from attacker-controlled infrastructure. The package uses obfuscated string construction to hide command-and-control domains and implements a DNS-TXT fallback channel for payload delivery.

    npmCompromised package
  4. resolvedcritical

    Malicious code in sme-rko-finance-front-operations-providers (npm)

    The npm package sme-rko-finance-front-operations-providers contained malicious code that downloads and executes platform-specific binaries from attacker-controlled Cloudflare Workers subdomains and DNS-TXT fallback channels upon require().

    npmCompromised package