ChainDrop: The Keyv and Cacheable npm Supply Chain Attack
On August 4, 2026, a sophisticated software supply chain attack dubbed ChainDrop struck the npm ecosystem through the compromise of a maintainer's GitHub account for the widely used Keyv and Cacheable open-source packages. The resulting self-propagating worm spread to over 2251 versions of 452 unique packages with approximately 2 billion monthly downloads, affecting organisations including Deliveroo, Ornikar, OneReach, Picsart, Qlik, and ServiceTitan.