A self-propagating worm called ChainDrop spread through more than 400 compromised npm packages by automatically republishing malicious updates, Microsoft Security Blog reported on August 4, 2026.
The worm was designed to steal credentials and move across software ecosystems without manual intervention. Microsoft Security Blog classified the attack as a supply chain compromise, meaning developers who pulled affected packages into their projects were exposed through the normal update process.
The blog's analysis covers the full attack chain and identifies which environments were affected. It also includes guidance for detecting ChainDrop activity, hunting for signs of infection, and remediating compromised systems.