ChainDrop npm Worm Hijacks 444 Packages with 2B Monthly Downloads
The ChainDrop worm, a variant of the Shai-Hulud attack, has taken over publishing rights for 444 npm packages with approximately 2 billion monthly downloads. Infection is triggered via malicious hooks in Claude Code and VS Code when opening a compromised branch or starting a session.
- 444 npm packages with ~2B monthly downloads compromised
- SessionStart hook in Claude Code triggers dropper at session start
- VS Code folderOpen task fires when opening repository
- Worm seeks npm, GitHub, cloud, Kubernetes, and Vault credentials
Read next
Security