A massive supply-chain attack dubbed 'ChainDrop' has compromised hundreds of npm packages, affecting over 500 million weekly downloads.
The malware plants hooks for Claude Code and VS Code, allowing attackers to harvest credentials from CI/CD environments.
Security researchers advise developers to audit their dependencies immediately, as the worm uses Ethereum-based dead-drop servers for command and control.