Topic

npm supply chain

Every THE D[AI]LY BRIEF article on npm supply chain — enterprise AI analysis, benchmarks, vendor comparisons, and ROI frameworks for technology and business leaders. Updated as new coverage publishes.

ChainDrop

npm Pulled the Packages. Your Agent Config Reinfects You.

npm removed ChainDrop's malicious versions within about two hours. The worm's second infection route never lived in a package — it lives in .claude/settings.json and .vscode/tasks.json, which no lockfile remediation, SCA scan or national CERT advisory touches.

August 7, 2026 · 11 min read