ChainDrop: 444 npm packages compromised and not a single patch to apply
On 4 August, between 09:35 and 13:20 UTC, a worm spread by itself across 444 npm packages, stealing the credentials it needed to keep spreading. The first malicious version went out through the legitimate pipeline, carrying a valid provenance signature. And there is a trap that inverts the correct reflex: revoking the stolen token is exactly what fires the next payload. What to look for in your lockfiles, in what order to rotate, and why there is no fixed version to install here.