Skip to content
theregister·

🚨ChainDrop Worm Infects 444 npm Packages

Your npm packages might be compromised

TL;DR

A new variant of the Shai-Hulud npm worm, ChainDrop, has infected 444 packages. It spreads through tarballs and dev-tool hooks, affecting millions of developers daily.

ChainDrop, a new variant of the Shai-Hulud npm worm, is spreading via tarballs and dev hooks, infecting 444 npm packages collectively downloaded about 2 billion times monthly. This worm targets deep infrastructure dependencies, making it particularly dangerous for widely used tools. Even if an infected package isn't installed, opening an affected Git branch in VS Code or Claude Code can trigger ChainDrop's startup hooks. The attack highlights the need to rethink how systems could be breached and emphasizes the importance of secure publishing practices.

ChainDrop Worm Infects 444 npm Packages — theregister

Key Points

1

ChainDrop spreads through tarballs and dev-tool hooks, infecting 444 npm packages.

2

Infected packages are collectively downloaded about 2 billion times monthly.

3

The worm targets widely used deep infrastructure dependencies, making it dangerous.

4

Even if not installed, opening an infected Git branch triggers ChainDrop's startup hooks.

5

Open source security firm SafeDep offers a list of compromised packages and version numbers.

Why It Matters

If you're using npm for package management, this is critical. ChainDrop infects deep infrastructure dependencies, making it hard to detect. Developers should check their .claude/settings.json and .vscode/tasks.json files for suspicious activity. Trusted publishing tools like GitHub Actions need re-evaluation.

npmwormChainDropvulnerabilitypackage-management

Frequently Asked Questions

Why does this matter?

If you're using npm for package management, this is critical. ChainDrop infects deep infrastructure dependencies, making it hard to detect. Developers should check their .claude/settings.json and .vscode/tasks.json files for suspicious activity. Trusted publishing tools like GitHub Actions need re-evaluation.

What happened?

A new variant of the Shai-Hulud npm worm, ChainDrop, has infected 444 packages. It spreads through tarballs and dev-tool hooks, affecting millions of developers daily.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,018 builders reading daily.

Also get