ChainDrop Turned Trusted npm Publishing into a Self-Propagating Attack

A new Shai-Hulud descendant spread through npm packages with legitimate-looking provenance. The incident shows why a trusted build path is not necessarily a trustworthy one. Security researchers identified a fast-moving npm supply-chain campaign on 4 August and named it ChainDrop.…








