chiprook
← Security
SecuritySeptember 17, 2026, 14:57

ChainDrop npm Worm Hijacks 444 Packages with 2B Monthly Downloads

The ChainDrop worm, a variant of the Shai-Hulud attack, has taken over publishing rights for 444 npm packages with approximately 2 billion monthly downloads. Infection is triggered via malicious hooks in Claude Code and VS Code when opening a compromised branch or starting a session.

ChainDrop npm Worm Hijacks 444 Packages with 2B Monthly Downloads
#Npm#Claude#Microsoft#GitHub
Read next
Security

NIO ES8 in Norwegian Mine: 90% of Traffic Went to Chinese Servers

Security

Fake LastPass Installers Pushed Kernel Driver That Killed 145 Security Tools

Security

Hacktron details attack chain that compromised OpenAI employee accounts

Security

iOS 27 lets apps ask your iPhone if you're being scammed