Pillar Security reported on August 4, 2026, that the ChainDrop npm worm planted malicious hooks in compromised repositories. The hooks trigger when a developer opens the workspace, posing a supply chain risk.
Pillar Security reported on August 4, 2026, that the ChainDrop npm worm planted malicious hooks in compromised repositories. The hooks trigger when a developer opens the workspace, posing a supply chain risk.