The ChainDrop malware campaign compromised the npm software package registry. This attack uses a Shai-Hulud family worm to infect over 1,300 packages. Affected libraries include Keyv and Cacheable. These compromised packages generate more than 2 billion monthly downloads.

The worm steals developer credentials to automatically republish packages with malicious code. Attackers target cloud service tokens and sensitive secrets within developer environments and CI/CD pipelines. The malware includes a dead man's switch that sabotages systems if stolen GitHub tokens are revoked. This incident highlights ongoing supply chain vulnerabilities in the open-source software ecosystem.