:
[SECURITY]■ STORY TIMELINE

CHAINDROP WORM INFECTS 1,300+ NPM PACKAGES

A self-propagating malware called ChainDrop has compromised over 1,300 packages on npm, affecting libraries with a combined 2 billion monthly downloads. Popular packages like Keyv, Cacheable, and flat-cache are among those infected.

3 SOURCESFIRST SEEN AUG 4, 11:01 AM► READ THE ARTICLE
Hacker News+0m

Article URL: https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack Comments URL: https://n…

Bleeping Computer+4h 23m

Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly do…

Techmeme+4h 43m

Bill Toulas / BleepingComputer: Researchers: ChainDrop, a Shai-Hulud-based worm, has compromised 1,300+ npm packages, li…