A self-spreading worm tore through npm on Tuesday. It poisoned hundreds of packages that huge swathes of the software world quietly rely on. Researchers named it ChainDrop. It is a bigger, meaner descendant of the smaller Shai-Hulud attack that hit the registry earlier this summer.
It began by hijacking the GitHub account of the developer behind keyv. That caching library is pulled in about 150 million times a week. From there it spread to its sibling packages, then to hundreds of others. Within two hours it had reached corporate names like Deliveroo, Qlik, Picsart and ServiceTitan. The affected packages draw billions of downloads a month.
The exact tally kept climbing, and researchers’ counts differed. The firms tracking it included BleepingComputer, Aikido and StepSecurity. They put the damage at hundreds of packages and well over 1,300 poisoned versions. npm has been hit before. This was among the largest.
It weaponised the industry’s own trust signals
Here is what made it dangerous. The attacker did not steal a token and upload the malware by hand. He pushed poisoned code into the projects’ main branches. Then he let each project’s own automated release pipeline publish it.







