Skip to main content

Tag: npm supply chain

1 article

Software development workspace with laptop, papers, and coffee cups, surrounded by technical books and equipment.

ChainDrop Worm Infiltrates npm Supply Chain, Evades Defenses

A sneaky new worm called ChainDrop has infiltrated the npm supply chain, infecting 444 packages that are downloaded a whopping 2 billion times each month. This stealthy attack uses a clever tactic, targeting package tarballs rather than repository source commits to evade defenses.

Analyst 207