ChainDrop is an npm worm whose operators planted malicious Claude Code SessionStart hooks and VS Code folderOpen tasks in compromised repositories. The malware triggers when a developer opens the workspace, rather than during installation. It was reported by Pillar Security on August 4, 2026.