A self-spreading worm poisoned hundreds of npm packages in hours, slipped past provenance checks, hid its controls on Ethereum, and hunted AI-tool keys.

A Keyv-linked npm worm poisoned 353 versions across 79 package names, stealing developer and CI credentials while repository hooks remained present.

Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.