:

CHAINDROP WORM INFECTS 1,300+ NPM PACKAGES

AI DESK1 MIN READ
TUE, AUG 4, 2026

■ AI-SUMMARIZED FROM 3 SOURCES ▸ TIMELINE

A self-propagating malware called ChainDrop has compromised over 1,300 packages on npm, affecting libraries with a combined 2 billion monthly downloads. Popular packages like Keyv, Cacheable, and flat-cache are among those infected.

Researchers have identified ChainDrop, a worm-type malware based on Shai-Hulud, actively spreading through the Node Package Manager registry. The attack represents a significant supply chain threat to JavaScript developers worldwide. The compromised packages span widely-used utilities in the Node.js ecosystem. Keyv, a popular key-value storage library, and flat-cache, a caching solution, are among the confirmed victims. The sheer download volume—2 billion per month across infected packages—means the malware has potential exposure to millions of projects and developers. ChainDrop operates as a self-propagating worm, meaning it can spread itself to other packages without manual intervention. This automated propagation mechanism allows it to reach deep into dependency chains, potentially affecting applications that indirectly use compromised libraries. The Shai-Hulud-based architecture of ChainDrop indicates sophisticated malware design. Developers and organizations using npm packages should treat this as a critical security incident. Immediate actions: - Audit projects for compromised dependencies - Update affected packages to patched versions - Monitor package.json and lock files for unexpected changes - Review npm account security settings The npm registry's security team has been notified. Users should follow official advisories from package maintainers for remediation guidance. This incident underscores ongoing vulnerabilities in open-source software supply chains and the need for stronger verification mechanisms in package repositories. Developers relying on npm should monitor security channels closely for updates on affected versions and available patches.

■ SOURCES

TechmemeHacker NewsBleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The North Carolina Ports Authority confirmed a cyberattack has disrupted IT systems across its major operations. The attack affects Port of Wilmington, Port of Morehead City, and Charlotte Inland Port.

JUST NOWSecurity Desk

Security researchers have identified a Chinese-linked spyware operation targeting victims across 13 countries, including the United States. The discovery came after operators made a critical operational security mistake.

2H AGOIndustry Desk

Roku collects extensive viewing data from its users. Here's how to limit what the company tracks.

3H AGOIndustry Desk

Artificial intelligence has revealed a long-overlooked browser security vulnerability that enterprises can no longer afford to ignore. Skyhigh Security explains why browsers have become essential control points for managing data, AI interactions, and modern work environments.

5H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.