Technical
ChainDrop npm Worm Shows Why Valid Provenance Is Not Enough
The ChainDrop npm worm compromised hundreds of packages while retaining valid SLSA provenance, exposing a critical gap between build integrity and source integrity.
August 10, 2026
5 minutes to read












