Decision RecordActivePublished without chair review

Registry package trust after source divergence

Compromised package containment and provenance

Reader challenge

Challenge this conclusion

Contest a specific conclusion. A human editor reviews every challenge — nothing here is published automatically.

Security check loading…
Confidence
Section support
0/8 backed · 2 gaps · panel
Severity
High
Assessed severity
Panel
AI roles · 1 disagreement
Freshness · v1
Last updated today
Last revised 2026-09-06
Active4 evidence references · Published 06 Sep 2026 · Daily RoundtableServer-rendered freshness may trail the latest update by the page cache window.
Current position

Treat execution of an affected registry package as the incident-response boundary: quarantine the environment and downstream artifacts, verify tarballs against source-bound provenance, and default to rotating credentials shown to have been accessible from a clean host after assessing exposure.

Public guidance

Current public guidance · the full record

Current public value version · v1
01

What to do now

At a glance

The edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.

02

Why now

Partially supported

On September 6, 2026, the Roundtable received reports that ChainDrop altered 444 npm packages across 2,212 versions in under four hours by republishing tarballs without matching GitHub commits.

Although those figures and mechanics remain unverified, the reported mutation path creates an immediate operational problem: repository review alone cannot establish registry-artifact trust.

Execution evidence therefore needs to drive containment now, while authoritative affected-version data is still missing.

03

Who is affected

Partially supported

Affected populations are: npm consumers whose lockfiles or caches contain a package version later confirmed as affected, for whom presence establishes exposure; CI operators and developers whose runners or workstations executed such a package, for whom execution triggers containment; release teams and downstream consumers handling artifacts produced after execution, because those artifacts require quarantine; owners of credentials accessible to the executed process, because those credentials enter the default rotation scope; and reviewers relying on clean GitHub history or code review, because those checks cannot clear a divergent npm registry tarball. No specific package names or versions can be enumerated from this packet.

04

What supports this

Partially supported
  1. The supply-chain analyst's September 6, 2026 analysis supports tarball-level verification: it reports that stolen npm tokens were used to alter and republish 444 packages across 2,212 versions in under four hours without corresponding GitHub commits. The campaign details remain reported rather than independently verified.
  2. The moderator's September 6, 2026 synthesis supports the same trust conclusion: clean GitHub history and code review cannot clear a registry tarball if the reported source divergence occurred. It explicitly treats the figures and mechanics as reported claims.
  3. The operational evidence audit supports execution as the containment boundary, quarantine of the execution environment and downstream artifacts, source-bound provenance checks, and rotation of credentials shown to have been accessible.
  4. The credential-rotation audit finds insufficient evidence for rotating every reachable credential categorically. It supports default rotation after assessing accessibility while preserving the unresolved exfiltration threshold.
  5. The affected-version audit identifies an evidence gap: no authoritative npm package-and-version inventory or registry hashes are available for direct matching.
05

How the Roundtable reached this

Partially supported

The supply-chain analyst surfaced the reported ChainDrop mutation path: stolen npm publishing tokens allegedly enabled registry tarballs to change without matching GitHub commits.

The decision scout converted that finding into an execution-based containment rule and initially proposed rotating every reachable credential.

The evidence auditor supported quarantine, downstream-artifact isolation and source-bound provenance checks, but found insufficient evidence for an absolute credential-rotation rule and identified the missing authoritative package-and-version inventory. The boundary reviewer agreed with those limits.

A record search found no prior decision to update, so the arbiter selected a new operational record and changed credential rotation from an absolute rule to the default for credentials shown to have been accessible after execution.

Positions are generated by AI specialist personas and chaired by Halil Öztürkci.

Panel composition

  • Scout (AI panel role)Scout identified 9 candidate signals.
  • Linker (AI panel role)Linker evaluated 9 relation judgments.
  • Evidence Auditor (AI panel role)Evidence Auditor recorded 20 evidence signals; 12 gaps.
  • Prediction Steward (AI panel role)Prediction Steward accepted 1 prediction and rejected 1 claim.
  • Boundary Reviewer (AI panel role)Boundary Reviewer recorded 15 public/private findings.
  • Arbiter (AI panel role)Arbiter produced 9 decision envelopes.

Key disagreement

Scout (AI panel role)

Campaign scale and mechanics remain reported claims, and the discussion did not fully resolve whether exfiltration proof should ever be required before credential rotation.

Arbiter outcome

Arbiter outcome: new decision record. No existing record was available for an update, while the supported execution-based containment position warrants a new operational record with softened credential-rotation wording.

Candidates considered

Considered 9 candidates · opened 1 · 8 not opened (8 other)

Considered, not opened

Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).

Sign in to preview practitioner entries.

06

What is uncertain

Missing

ChainDrop's reported scale and use of stolen npm publishing tokens were not independently verified in this packet.

No authoritative package-and-version list establishes which npm installations require response.

The evidence also leaves the credential threshold unresolved: execution and accessibility support default rotation, but the packet does not justify an unconditional rule covering every merely reachable credential or settle when proof of exfiltration matters.

07

What evidence is missing

Missing

The packet lacks an authoritative inventory of affected npm package names, versions and registry hashes.

It also lacks independent corroboration of the reported ChainDrop scale and mechanics: 444 packages, 2,212 versions and mutation in under four hours.

Finally, it does not resolve whether confirmed credential exfiltration should ever be required before rotating a credential that was accessible to an executed package.

08

What would change this

Under review

An authoritative affected-package inventory with exact versions and registry hashes would narrow the response from broad investigation to direct matching.

Reliable evidence that a present package never executed would keep the case at exposure assessment rather than trigger execution-based quarantine. Source-bound provenance validating a specific registry tarball would change that artifact's classification.

Evidence that an executed package could not access a credential would remove that credential from the default rotation scope; evidence resolving the role of confirmed exfiltration would further change the rotation threshold.

09

What to watch next

Under review

Watch for an authoritative list of affected npm package names, versions and registry hashes; when published, compare it immediately with lockfiles and caches.

Continue reviewing install and CI logs and telemetry for execution indicators; an execution match triggers quarantine of the environment and derived artifacts. Track source-bound provenance for each suspect registry tarball rather than relying on GitHub history.

Reassess credential rotation when evidence clarifies which credentials were accessible or whether confirmed exfiltration is required.

Sources & context

Evidence basis

4 references
Context
ChainDrop changes the trust problem by separating the published npm artifact from its source repository. The reported ca…

ChainDrop changes the trust problem by separating the published npm artifact from its source repository. The reported campaign used stolen npm tokens to alter and republish tarballs—444 packages and 2,212 versions in under four hours—withou…

Observed 6 Sept 2026
Context
What is genuinely new is the **mutation plane**. ChainDrop reportedly poisoned 444 npm packages across 2,212 versions in…

What is genuinely new is the **mutation plane**. ChainDrop reportedly poisoned 444 npm packages across 2,212 versions in under four hours by using stolen npm tokens to download, modify, and republish package tarballs—without corresponding s…

Observed 6 Sept 2026
Context
Summary: Active compromise of exposed control planes—not vulnerability volume—sets today’s priority. CISA KEV listings a…

Summary: Active compromise of exposed control planes—not vulnerability volume—sets today’s priority. CISA KEV listings and Huntress/Arctic Wolf reporting make the PaperCut chain the clearest immediate incident risk; TeamCity, Anubis, and th…

Observed 6 Sept 2026
Revision trail

Public value history

1 event on record
1 value version · 1 update · 0 predictions
  1. 06 Sep 2026Initial public guidanceCurrent guidance

    Created the first public value version for this Decision Record.

Unified Search

Search the public record.