Bill Toulas / BleepingComputer:
Researchers: ChainDrop, a Shai-Hulud-based worm, compromised 1,300+ npm packages, including Keyv and Cacheable, with a combined 2B monthly downloads — Self-propagating malware named ‘ChainDrop’ has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.



