Supply Chain Attack
ChainDrop, a Shai-Hulud npm Worm, Poisons 444 Packages and Evades Standard Defenses
ChainDrop, a variant of the Shai-Hulud npm worm, has been documented poisoning 444 packages and spreading through tarballs and dev-tool hooks while slipping past standard defenses. Here is what the report confirms, what it does not, and how Node.js teams can verify their exposure.