build1 publisher
ChainDrop executes from a checked-in agent config the moment a coding session starts
GitGuardian says the ChainDrop worm reached 444 npm packages by planting a SessionStart hook in Claude Code and a folderOpen task in VS Code, and the publishing credential it steals is used to republish inside the same session.
Publishers:dev.to
Reality
- Evidence45
- Adoption55
- Hype gap+22
- Incentives80
- Confidence42