Supply-chain attacks: package cooldowns and policy checks for npm, PyPI and NuGet
This story is from 2026-08-28. It is preserved in the archive; the latest stories are on the live feed.
On 4 August 2026, a self-propagating worm called ChainDrop tore through npm. BleepingComputer reported more than 1,300 compromised packages with about two billion monthly downloads between them, including keyv, cacheable, flat-cache and file-entry-cache. The poisoned releases carried a "preinstall"…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-08-28 00:50 · DEV Community — AI
Supply-chain attacks: package cooldowns and policy checks for npm, PyPI and NuGet