• Another npm worm

    From LWN.net@618:250/24 to All on Wed Aug 5 06:40:09 2026


    StepSecurity is

    reporting the emergence of a new worm affecting npm packages.
    The design of the worm is nothing new, but the rapidity with which it is exploiting captured npm
    packager credentials is noteworthy.

    TL;DR: A self-propagating worm, which we are calling ChainDrop, is spreading rapidly through the npm ecosystem. So far 435 packages and more than 1,550 compromised versions have been flagged, starting with keyv@6.0.0. If you are using any of the packages listed below, assume your environment is compromised. We are still investigating the full scope; check back on this post for updates.

    https://lwn.net/Articles/1087108/
    --- SBBSecho 3.37-Linux
    * Origin: Palantir * palantirbbs.ddns.net * Pensacola, FL * (618:250/24)