Massive ChainDrop npm supply-chain attack infects hundreds of packages
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 npm packages with a combined 2 billion monthly downloads. The attack represents a large-scale supply chain compromise affecting the Node Package Manager ecosystem.
- Disclosed
- Last updated
- Blast radius
- 1,300+ npm packages with 2 billion combined monthly downloads
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- npm packages (multiple)Self-propagating malware 'ChainDrop' compromised 1,300+ packages
A self-propagating malware campaign named 'ChainDrop' has compromised over 1,300 packages in the npm registry. The affected packages collectively receive approximately 2 billion monthly downloads, indicating widespread potential exposure.
The malware's self-propagating nature suggests it may be designed to spread across package dependencies, potentially infecting additional packages and downstream consumers. The scale of the compromise—affecting more than 1,300 packages—indicates a significant supply chain attack with broad reach across the Node.js ecosystem.
As of the report date (August 4, 2026), the attack appears to be ongoing, with the malware actively compromising packages in the npm registry.
Remediation
- Audit npm package dependencies for presence of ChainDrop malware
- Review package.json and lock files for unexpected or suspicious package additions
- Monitor npm package downloads and dependencies for anomalous behavior
- Update to patched versions of affected packages once available
- Consider implementing package integrity verification and signed package requirements
- Review npm account security and enable two-factor authentication on npm accounts
Sources
- Massive ChainDrop npm supply-chain attack infects hundreds of packages · BleepingComputer
Cite this entry
"Massive ChainDrop npm supply-chain attack infects hundreds of packages." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 4, 2026; last updated August 4, 2026. https://supplychainattack.org/incident/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages-1pj9ly
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in @onereach/si-text-message
Malware was discovered in the npm package @onereach/si-text-message. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @servicetitan/assist-ui
Malware was discovered in the npm package @servicetitan/assist-ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @onereach/orest-cli
Malware was discovered in the npm package @onereach/orest-cli. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in @servicetitan/install
Malware was discovered in the npm package @servicetitan/install. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package