BleepingComputer · Aug 4, 2026 · 1 min read · Original story Massive ChainDrop npm supply-chain attack infects hundreds of packages Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. Tagged: Supply chain