Skip to content
supplychainattack.orgSupply chain attack incident catalog
activecritical

Massive ChainDrop npm supply-chain attack infects hundreds of packages

Self-propagating malware named 'ChainDrop' has compromised more than 1,300 npm packages with a combined 2 billion monthly downloads. The attack represents a large-scale supply chain compromise affecting the Node Package Manager ecosystem.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
1,300+ npm packages with 2 billion combined monthly downloads
Ecosystems
Attack vectors
Threat actor
Affected entities
  • npm packages (multiple)Self-propagating malware 'ChainDrop' compromised 1,300+ packages

A self-propagating malware campaign named 'ChainDrop' has compromised over 1,300 packages in the npm registry. The affected packages collectively receive approximately 2 billion monthly downloads, indicating widespread potential exposure.

The malware's self-propagating nature suggests it may be designed to spread across package dependencies, potentially infecting additional packages and downstream consumers. The scale of the compromise—affecting more than 1,300 packages—indicates a significant supply chain attack with broad reach across the Node.js ecosystem.

As of the report date (August 4, 2026), the attack appears to be ongoing, with the malware actively compromising packages in the npm registry.

Remediation

  • Audit npm package dependencies for presence of ChainDrop malware
  • Review package.json and lock files for unexpected or suspicious package additions
  • Monitor npm package downloads and dependencies for anomalous behavior
  • Update to patched versions of affected packages once available
  • Consider implementing package integrity verification and signed package requirements
  • Review npm account security and enable two-factor authentication on npm accounts

Sources

  1. Massive ChainDrop npm supply-chain attack infects hundreds of packages · BleepingComputer

Cite this entry

"Massive ChainDrop npm supply-chain attack infects hundreds of packages." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 4, 2026; last updated August 4, 2026. https://supplychainattack.org/incident/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages-1pj9ly

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. activecritical

    Malware in @onereach/si-text-message

    Malware was discovered in the npm package @onereach/si-text-message. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2. containedcritical

    Malware in @servicetitan/assist-ui

    Malware was discovered in the npm package @servicetitan/assist-ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  3. containedcritical

    Malware in @onereach/orest-cli

    Malware was discovered in the npm package @onereach/orest-cli. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  4. activecritical

    Malware in @servicetitan/install

    Malware was discovered in the npm package @servicetitan/install. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.

    npmCompromised package