ChainDrop: The npm Worm That Poisoned 444 Packages in Under Four Hours
On the morning of 4 August 2026, a single compromised developer account set off the fastest self-spreading software supply chain incident the open source ecosystem has seen. Within four hours, malicious code had inserted itself into 444 software packages across 2,212 published versions, jumping automatically from one company's build system to the next by stealing credentials along the way. This briefing explains what happened in plain terms, who is exposed, and the small number of decisions leadership needs to make this week.
Aug 05, 2026 • 07:40 UTC