Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. This incident highlights the persistent vulnerability of software supply chains, where a single compromise can cascade through numerous downstream projects and applications.

https://meta-news.info/ver/over-400-npm-packages-infected-in-chaindrop-supply-chain-attack