- Sources: primary, discussion
- Summary: This archive covered the campaign on 2026-08-04, 2026-08-05 and 2026-08-06. The report adds the ChainDrop name attributed to Microsoft, a consolidated count of 444 packages across multiple publishers with about 2 billion monthly downloads, and the propagation detail that the worm rebuilds package tarballs to carry its payload rather than committing to source, so reviewing the repository shows no evidence of tampering. It repeats the editor and agent hook vector this archive covered on 2026-08-06, naming
.claude/settings.json and .vscode/tasks.json as the files to check across every branch. No list of affected package names and versions has been published, and every figure traces to The Register and ActiveState rather than to a registry advisory. - Why it matters: Repository review does not clear a package under this campaign, so verification has to run against the published tarball.
- Follow-up: Watch for a registry advisory that confirms the package count and names the affected packages and versions.
send feedback on this story