INCIDENT EVIDENCE GRAPH
Massive ChainDrop npm supply-chain attack infects hundreds of packages
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. [...]
- Victim: npm users and package consumers
- Actor: ChainDrop
- Method: Self-propagating malware compromised npm packages