ChainDrop worm crawls into npm supply chain, evades standard defenses

Shai-Hulud variant poisons 444 packages, spreads via tarballs and dev-tool hooks. This incident highlights the persistent and evolving threat to the software supply chain, demonstrating that attackers are finding new ways to compromise widely used package repositories.

https://meta-news.info/ver/chaindrop-worm-crawls-into-npm-supply-chain-evades-standard-defenses