ChainDrop Worm Infects 444 npm Packages: Why Your Web Dev Pipeline Could Be Compromised
A stealthy new npm supply-chain worm called ChainDrop has poisoned 444 packages collectively downloaded around 2 billion times a month, hiding its tracks by propagating through tarballs rather than source commits. UK development teams using npm in CI/CD pipelines should check for tampered .claude and .vscode configuration files across every branch, not just main.







