ChainDrop npm supply-chain attack infects over 1,300 packages; worm spreads by making malware look legitimate
A self-spreading worm named ChainDrop tore through npm, poisoning hundreds of packages that the software world relies on. The attack infected over 1,300 packages by making the malware appear perfectly legitimate, according to The Next Web.