🚨ChainDrop Worm Infects 444 npm Packages
Your npm packages might be compromised
TL;DR
A new variant of the Shai-Hulud npm worm, ChainDrop, has infected 444 packages. It spreads through tarballs and dev-tool hooks, affecting millions of developers daily.
ChainDrop, a new variant of the Shai-Hulud npm worm, is spreading via tarballs and dev hooks, infecting 444 npm packages collectively downloaded about 2 billion times monthly. This worm targets deep infrastructure dependencies, making it particularly dangerous for widely used tools. Even if an infected package isn't installed, opening an affected Git branch in VS Code or Claude Code can trigger ChainDrop's startup hooks. The attack highlights the need to rethink how systems could be breached and emphasizes the importance of secure publishing practices.

Key Points
ChainDrop spreads through tarballs and dev-tool hooks, infecting 444 npm packages.
Infected packages are collectively downloaded about 2 billion times monthly.
The worm targets widely used deep infrastructure dependencies, making it dangerous.
Even if not installed, opening an infected Git branch triggers ChainDrop's startup hooks.
Open source security firm SafeDep offers a list of compromised packages and version numbers.
Why It Matters
If you're using npm for package management, this is critical. ChainDrop infects deep infrastructure dependencies, making it hard to detect. Developers should check their .claude/settings.json and .vscode/tasks.json files for suspicious activity. Trusted publishing tools like GitHub Actions need re-evaluation.
Frequently Asked Questions
Why does this matter?
If you're using npm for package management, this is critical. ChainDrop infects deep infrastructure dependencies, making it hard to detect. Developers should check their .claude/settings.json and .vscode/tasks.json files for suspicious activity. Trusted publishing tools like GitHub Actions need re-evaluation.
What happened?
A new variant of the Shai-Hulud npm worm, ChainDrop, has infected 444 packages. It spreads through tarballs and dev-tool hooks, affecting millions of developers daily.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,018 builders reading daily.