CyberSecurity News
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
SecurityWeek
· August 5, 2026AI summary
A supply chain attack known as ChainDrop has resulted in the infection of over 400 NPM packages. The malware involved in the attack is capable of stealing and exfiltrating secrets, as well as propagating itself by using stolen credentials from NPM and GitHub.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to SecurityWeek.

