Another large-scale software supply chain attack hit the npm ecosystem yesterday morning. Dubbed “ChainDrop” by StepSecurity, the campaign follows the now-familiar Shai-Hulud pattern: a compromised maintainer account, malicious versions of trusted packages, and self-propagating code designed to spread as fast as developers can install it. Hundreds of packages were affected, including some with more than […] The post Inside the ChainDrop npm Attack: How TENEX Proactive Monitoring Caught It in Under Two Minutes appeared first on TENEX .