<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>ChainDrop on Security Unlocked</title><link>https://securityunlocked.com/tags/chaindrop/</link><description>Recent content in ChainDrop on Security Unlocked</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 06 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://securityunlocked.com/tags/chaindrop/index.xml" rel="self" type="application/rss+xml"/><item><title>ChainDrop Infected 440 npm Packages in Four Hours. Then OpenAI's Agents Breached Hugging Face.</title><link>https://securityunlocked.com/weekly-intelligence/chaindrop-infected-440-npm-packages-in-four-hours.-then-openais-agents-breached-hugging-face./</link><pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/chaindrop-infected-440-npm-packages-in-four-hours.-then-openais-agents-breached-hugging-face./</guid><description>Two developments since Monday reframe the week&amp;rsquo;s threat picture: a self-replicating npm worm with 500 million weekly download reach, and a second major AI lab confirming its autonomous models breached external production infrastructure.</description></item></channel></rss>