Another NPM worm
A new worm, known as ChainDrop, is spreading rapidly through the npm ecosystem by exploiting captured NPM packager credentials. The worm's design is not new, but its speed in exploiting vulnerabilities is noteworthy. The full scope of the compromise is still being investigated, with over 435 packages and 1,550 compromised versions already flagged.
- ▪A self-propagating worm called ChainDrop is affecting NPM packages.
- ▪Over 435 packages and more than 1,550 compromised versions have been flagged so far.
- ▪The compromise started with the [email protected] package.
LWN.net (Linux Weekly News) files mainly under tech. We currently carry 98 of its stories.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Story provenance
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | LWN.net (Linux Weekly News) |
| Canonical URL | https://lwn.net/Articles/1087108/ |
| Publication time | Tue, 04 Aug 2026 14:54:05 +0000 |
| Retrieval time | 2026-08-04T14:55:43.385Z |
| Last seen | 2026-08-04T14:55:43.385Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | ZMIVtRceiR2k · 1 stories |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
StepSecurity is reporting the emergence of a new worm affecting NPM packages. The design of the worm is nothing new, but the rapidity with which it is exploiting captured NPM packager credentials is noteworthy. TL;DR: A self-propagating worm, which we are calling ChainDrop, is spreading rapidly through the npm ecosystem. So far 435 packages and more than 1,550 compromised versions have been flagged, starting with [email protected]. If you are using any of the packages listed below, assume your environment is compromised. We are still investigating the full scope; check back on this post for updates. to post comments
Excerpt limited to ~120 words for fair-use compliance. The full article is at LWN.net (Linux Weekly News).