ChainDrop, a self-propagating worm, has compromised more than 1,300 npm packages responsible for 2 billion combined monthly downloads, including Keyv, Cacheable and utilities tied to Deliveroo, Picsart, Qlik and others. The malware steals a broad array of developer and cloud credentials from infected systems and CI/CD environments, requiring any impacted machine to be treated as fully breached.

By ~18:10 UTC on Aug 5, npm and maintainers reverted all 11 primary carriers (e.g. keyv) to clean versions, removed some scoped packages (e.g. @servicetitan, @nebula.js) wholesale, and published clean releases for others (e.g. @thiennq/docs-viewer 1.6.4); a few (e.g. @picsart/ai-sdk@3.32.2, @deliveroo/reevent@1.0.1) remained live with malicious versions as cleanup continued.
npm has begun unpublishing malicious versions and reverting some carriers (e.g., keyv) to prior clean releases, with cleanup reported as ongoing.
Anyone who ran npm install against an affected version would have had setup.mjs execute automatically before their install completed.
Its code also contains self-propagation logic that lets it compromise packages belonging to other maintainers who depended on an earlier infected module.
Treat every npm install from the past days as a potential credential breach; rotate all GitHub, npm, cloud, and secrets immediately and audit CI runners for npm-cache.com traffic.
Tap a lens to see what this story means for you.
Reader-supported · The Brief
Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
The fifth beta of iOS 27 arrived this week alongside an alleged iPhone 18 Pro Max battery leak showing 5,391 mAh capacity, screen protector images confirming asymmetric corners on the foldable iPhone Ultra, and Mark Gurman's report on radical Apple Watch redesigns that may include round faces and screenless trackers.
ShinyHunters obtained and later leaked personal data belonging to 1.6 million RingCentral accounts after a July breach. The incident touched only a limited portion of the cloud communications provider’s customers and left core services untouched.
SpaceX has completed its $60 billion acquisition of AI coding startup Cursor, granting the company access to the world's largest GPU fleet for lower-cost model development. The deal, which began with an April partnership and follows SpaceX's merger with xAI, has already produced Grok 4.5 and 4.6 focused on coding and real-world tasks.