A new and highly evasive worm, known as ChainDrop, has been identified in the npm supply chain. This variant of the Shai-Hulud npm worm has managed to infect 444 packages, utilizing unconventional methods to spread and evade detection.
Key Insights
ChainDrop spreads through tarballs and dev-tool hooks, avoiding typical methods of breaching open source repositories. It propagates by rebuilding tarballs to include its own payload, without leaving any evidence in the source code repositories. This sophisticated approach allows the worm to remain undetected, despite being downloaded approximately 2 billion times a month.









