Inside a Self-Propagating npm Worm

Reported 07 Aug 2026 by otx · Severity: medium

A self-propagating npm worm dubbed ChainDrop infected over 400 packages downloaded hundreds of millions of times weekly, including popular packages like keyv and cacheable-request. The worm steals cloud credentials, npm and GitHub tokens, SSH keys, and sensitive developer data wh