ELSEIF
Your brief EB
251 stories from 105 feeds 328 clusters Refreshed 1 minute ago next pull 12:38

DEV TOOLS Signal 447

ChainDrop worm infects 444 npm packages, spreads via tarballs and IDE hooks

ChainDrop, a new variant of the Shai-Hulud npm worm, infected 444 npm packages by propagating through tarballs and IDE configuration hooks rather than source commits, evading standard repository defenses.

WHY IT MATTERS

ChainDrop evades typical supply chain defenses by spreading through tarballs rather than source commits, meaning reviewing repository code won't reveal infection. It also places hooks in VS Code and Claude Code configuration files, so simply opening an infected branch can compromise credentials and continue the cycle.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

ChainDrop infected 444 npm packages collectively downloaded about 2 billion times per month, targeting infrastructure dependencies like keyv, flat-cache, and cache-manager.

02

The worm propagates via tarballs rather than source commits, so reviewing repository code won't reveal tampering.

03

Opening an infected Git branch in VS Code or Claude Code triggers background tasks that harvest credentials, beginning the infection cycle anew.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
www.theregister.com - Articles ChainDrop worm crawls into npm supply chain, evades standard defenses Open ↗