Security· August 15, 2026 at 10:31 a.m.
NPM Supply Chain Attack by Shai-Hulud Variant Evades Standard Defenses
Key takeaways
- 444 npm packages infected
- Targets deep infrastructure dependencies
- Spreads via tarballs and dev-tool hooks
A new variant of the Shai-Hulud npm worm, named 'ChainDrop', has infiltrated 444 packages from multiple publishers, posing a significant threat to the npm community. The attack targets deep infrastructure dependencies and spreads via tarballs and dev-tool hooks, bypassing standard open source repository safeguards. Unlike traditional methods, ChainDrop doesn't rely on breaching repository source commits but instead uses self-replication through tarballs.