{"id":242287,"date":"2026-08-06T16:45:21","date_gmt":"2026-08-06T21:45:21","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/08\/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages"},"modified":"2026-08-06T16:45:21","modified_gmt":"2026-08-06T21:45:21","slug":"massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/08\/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages","title":{"rendered":"Massive ChainDrop npm supply-chain attack infects hundreds of packages"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages.jpg\"><\/a><\/p>\n<p>Self-propagating malware named \u2018ChainDrop\u2019 has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.<\/p>\n<p>Infected packages include very popular ones such as Keyv and Cacheable, flat-cache and file-entry-cache, all caching utilities from the same maintainer.<\/p>\n<p>The supply-chain attack started after the threat actor compromised the GitHub account of Keyv\u2019s maintainer, and quickly spread to packages associated with major organizations such as Deliveroo, Ornikar, OneReach, Picsart, Qlik, and ServiceTitan.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Self-propagating malware named \u2018ChainDrop\u2019 has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. Infected packages include very popular ones such as Keyv and Cacheable, flat-cache and file-entry-cache, all caching utilities from the same maintainer. The supply-chain attack started after the threat actor compromised the [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34],"tags":[],"class_list":["post-242287","post","type-post","status-publish","format-standard","hentry","category-cybercrime-malcode"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/242287","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=242287"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/242287\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=242287"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=242287"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=242287"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}