ChainDrop Malware Infects Over 1,300 npm Packages in Record Supply Chain Poisoning Campaign
ChainDrop malware has infected more than 1,300 npm packages with a combined monthly download volume of 2 billion, marking one of the largest supply chain poisoning incidents recorded to date. If you updated an npm dependency in the past week, your development credentials may already have been exfiltrated to attacker infrastructure.
The attack begins when an infected package executes inside a developer environment. It first reads the local .npmrc file to extract npm authentication tokens. Next, it scans for SSH keys and Git configuration files to obtain access to code repositories. Finally, the malware uses the stolen npm token to publish malicious updates to any other packages owned by the same account, creating a self-replicating infection chain.
Simultaneously, the Open VSX marketplace removed 77 malicious extensions that used a “twin” naming strategy to impersonate legitimate developer tools. These extensions collected hostnames, repository metadata, CI environment variables, and credential files. Their combined download count exceeded one million.
A third vector, dubbed HalluSquatting, targets AI coding assistants. Attackers monitor suggestions from tools such as GitHub Copilot, Cursor, and Claude Code for non-existent package names. Once a frequently hallucinated name is identified, the attacker registers the package with malicious code. Developers who accept the AI-generated import statement unknowingly install the backdoor.
The three incidents underscore the expanding attack surface of modern software supply chains. With more than three million packages in the npm ecosystem and thousands of new versions published daily, traditional “trust your direct dependencies” approaches are no longer sufficient. Defenses must now cover lockfiles, token scoping, and verification of AI-suggested packages.
Recommended mitigations include pinning all direct and transitive dependencies with integrity hashes, issuing npm tokens with publish rights only when necessary, and manually checking any package name suggested by an AI assistant for recent registration dates or missing maintainer information.
Related articles
Security Researcher Builds SAST Scanner for AI-Generated Code and Audits 3,800 Public Repositories
A developer released AigisSAST, a lightweight open-source static analysis tool written in pure Python with no external dependencies, specifically tuned to detect common mistakes made by AI coding assistants. The scanner was run across roughly 3,800 repositories ranging from small pet projects to popular open-source platforms. It identified thousands of potential secrets and misconfigurations, yet manual review reduced the number of genuine leaks to approximately 30 cases, mostly Telegram bot tokens, database credentials, and committed .env files. The project also examined 471 production-grade Telegram bots handling payments and VPN services, uncovering 31 repositories that exposed real credentials either in current code or in Git history. AigisSAST includes 21 detection rules, 193 regression tests, automatic remediation via the fix command, and seamless integration with GitHub Actions. The author deliberately avoided validating any discovered keys to stay within ethical research boundaries.
Vendor Responsibility in Open Source: Licensing Obligations Exposed by Sonatype Nexus Changes
The article examines how vendors building products on copyleft open source projects like Nexus Repository OSS inherit significant legal and security responsibilities under licenses such as EPL 1.0. Sonatype's February 2025 shift from regular OSS binary releases to a limited Community Edition forces downstream vendors to handle their own builds, patch porting, and compliance disclosures. This change highlights the second part of copyleft licenses that outlines obligations for distributors, including revealing modifications and assuming liability for the final product. Security implications arise because critical vulnerabilities in the upstream project must now be tracked and patched by the vendor, with delays creating measurable supply chain risks. The piece provides a practical checklist for buyers to assess licensing hygiene, SBOM availability, and vulnerability response times in any open source-based solution.
PhantomSub Campaign Deploys 101 Malicious npm Packages to Hijack WhatsApp Accounts for Unauthorized Channel Subscriptions
Researchers at OX Security uncovered 101 malicious npm packages tied to the PhantomSub campaign that abuse connected WhatsApp accounts to subscribe users to promotional channels without consent. The packages disguise themselves as modified versions of the open-source Baileys library used for WhatsApp automation. Attackers rely on authenticated sessions rather than simple package installation, allowing them to control subscriptions through lists stored on GitHub, in plaintext, or as encoded identifiers. The packages have accumulated roughly 490,000 downloads, including 116,000 in the past 30 days, though the exact number of compromised accounts remains unknown. As of 28 September, npm had removed only 16 of the identified packages. The operation ultimately benefits channels selling bots, game resources, accounts, and promotion services by inflating subscriber counts while disabling notifications to hide the activity.
AI Model Hallucinations Fuel Slopsquatting Attacks on PyPI and npm Registries
Researchers identified 139 package names consistently hallucinated by five different AI models across Python and JavaScript ecosystems. Seven of these names are already registered on PyPI and npm, including one previously used to distribute malware. The attack vector, termed slopsquatting, allows attackers to register AI-suggested package names and execute code with developer privileges during installation. One package, metro-evaluator, contained malicious code removed by npm in December 2025, while another empty package css-color-stop began receiving downloads after the list was published. Real projects such as odf and lusid now occupy names that AI models recommend, causing developers to install unrelated software. Studies show hallucination rates between 4.62% and 21.7% depending on the model, with commercial models performing better than open-source ones. The findings highlight risks when AI coding agents execute dependency installation commands without human verification.