CyberSecurityBoardThreat Intel · CVEs · Products

Tag: Supply Chain

Malware

ChainDrop npm Worm Uses AI Agent Hooks

ChainDrop is an npm worm whose operators planted malicious Claude Code SessionStart hooks and VS Code folderOpen tasks in compromised repositories. The…

ChainDrop Claude Code npm Supply Chain
August 7, 2026
Cyber Products

Keyv: npm Package and Worm Vector

Keyv is an npm package that was compromised in the August 2026 worm campaign. The malicious keyv@6.0.0 release included a preinstall script…

Keyv malware npm Supply Chain
August 4, 2026
Cyber Companies

Pillar Security Reports ChainDrop Worm

Pillar Security reported on August 4, 2026, that the ChainDrop npm worm planted malicious hooks in compromised repositories. The hooks trigger when…

malware npm Pillar Security Supply Chain
August 4, 2026
Cyber Companies

Xanadu’s mrmustard Library Poisoned

Xanadu's photonic quantum computing Python library, mrmustard, was compromised with a poisoned version that ran an information stealer. The attack involved breaching…

information stealer mrmustard Supply Chain Xanadu
August 3, 2026