A self-propagating malware called ChainDrop has compromised over 1,300 packages on npm, affecting libraries with a combined 2 billion monthly downloads. Popular packages like Keyv, Cacheable, and flat-cache are among those infected.
Researchers have identified ChainDrop, a worm-type malware based on Shai-Hulud, actively spreading through the Node Package Manager registry. The attack represents a significant supply chain threat to JavaScript developers worldwide.
The compromised packages span widely-used utilities in the Node.js ecosystem. Keyv, a popular key-value storage library, and flat-cache, a caching solution, are among the confirmed victims. The sheer download volume—2 billion per month across infected packages—means the malware has potential exposure to millions of projects and developers.
ChainDrop operates as a self-propagating worm, meaning it can spread itself to other packages without manual intervention. This automated propagation mechanism allows it to reach deep into dependency chains, potentially affecting applications that indirectly use compromised libraries.
The Shai-Hulud-based architecture of ChainDrop indicates sophisticated malware design. Developers and organizations using npm packages should treat this as a critical security incident.
Immediate actions:
- Audit projects for compromised dependencies
- Update affected packages to patched versions
- Monitor package.json and lock files for unexpected changes
- Review npm account security settings
The npm registry's security team has been notified. Users should follow official advisories from package maintainers for remediation guidance. This incident underscores ongoing vulnerabilities in open-source software supply chains and the need for stronger verification mechanisms in package repositories.
Developers relying on npm should monitor security channels closely for updates on affected versions and available patches.
The North Carolina Ports Authority confirmed a cyberattack has disrupted IT systems across its major operations. The attack affects Port of Wilmington, Port of Morehead City, and Charlotte Inland Port.
Security researchers have identified a Chinese-linked spyware operation targeting victims across 13 countries, including the United States. The discovery came after operators made a critical operational security mistake.
Artificial intelligence has revealed a long-overlooked browser security vulnerability that enterprises can no longer afford to ignore. Skyhigh Security explains why browsers have become essential control points for managing data, AI interactions, and modern work environments.