ChainDrop worm hijacks Claude Code and VS Code configs to spread through npm

A self-replicating worm called ChainDrop compromised 444 npm packages, including keyv, flat-cache, and cache-manager, packages with a combined 2 billion monthly downloads. Microsoft and other researchers identified the campaign on August 4, and all infected packages have since been pulled from the registry.
ChainDrop is a variant of Shai-Hulud, the worm that first surfaced in September 2025. What makes this version different is where it hides. Instead of modifying package source or committing changes to a repository, where a code review or standard repo scan would likely catch it, ChainDrop rewrites the published tarball directly. ActiveState CEO Abby Kearns described the technique plainly: it skips the usual methods of breaching open source repository defenses entirely.
The worm activates through configuration files developers rarely audit: .vscode/tasks.json and .claude/settings.json. Once triggered, it searches shell configs and environment variables for npm tokens, cloud credentials, and GitHub access, then uses any GitHub credentials it finds to commit its own malicious configuration into repository branches, spreading further without ever touching a pull request.
For any team running Claude Code or VS Code against real dependencies, this changes what counts as a plausible attack surface. Editor and agent config files need to be treated as executable code, not inert settings, and audited across every branch, not just main. SafeDep has published a list of confirmed-compromised packages worth cross-referencing against current lockfiles. Longer term, moving package publishing to a trusted pipeline like GitHub Actions closes the specific gap ChainDrop exploited: tarballs assembled and signed by CI, not pushed from a developer's local machine where a stolen token does the most damage.