FR
live
tag

#npm

ChainDrop infects 1,300 npm packages and 2 billion monthly downloads

A self-propagating **supply-chain** attack named **ChainDrop** compromised over **1,300 packages** on the **npm** registry on **August 4, 2026**. The infected packages accounted for **2 billion monthly downloads** and reached organizations including **Deliveroo**, **Qlik**, and **ServiceTitan**. Audit your dependencies now.

Type at least two characters.

navigate open esc dismiss