ChainDrop npm Attack Compromises Hundreds of Packages
Reported 06 Aug 2026 by otx · Severity: medium
A sophisticated software supply chain attack named ChainDrop has infected hundreds of npm packages, including popular caching libraries with millions of weekly downloads. Beginning August 4, 2026, attackers compromised a GitHub account of a keyv package maintainer, injecting mali