INCIDENT EVIDENCE GRAPH

Massive ChainDrop npm supply-chain attack infects hundreds of packages

Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. [...]

Primary evidence

  1. Massive ChainDrop npm supply-chain attack infects hundreds of packages

中文