Decision RecordActivePublished without chair review
CRT-2026-025406 Sep 2026MORNING EDITIONDaily Roundtable
Registry package trust after source divergence
Treat execution of an affected registry package as the incident-response boundary: quarantine the environment and downstream artifacts, verify tarballs against source-bound provenance, and default to rotating credentials shown to have been accessible from a clean host after assessing exposure.
Current public guidance · the full record
What to do now
At a glanceThe edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.
Why now
Partially supportedOn September 6, 2026, the Roundtable received reports that ChainDrop altered 444 npm packages across 2,212 versions in under four hours by republishing tarballs without matching GitHub commits.
Although those figures and mechanics remain unverified, the reported mutation path creates an immediate operational problem: repository review alone cannot establish registry-artifact trust.
Execution evidence therefore needs to drive containment now, while authoritative affected-version data is still missing.
Who is affected
Partially supportedAffected populations are: npm consumers whose lockfiles or caches contain a package version later confirmed as affected, for whom presence establishes exposure; CI operators and developers whose runners or workstations executed such a package, for whom execution triggers containment; release teams and downstream consumers handling artifacts produced after execution, because those artifacts require quarantine; owners of credentials accessible to the executed process, because those credentials enter the default rotation scope; and reviewers relying on clean GitHub history or code review, because those checks cannot clear a divergent npm registry tarball. No specific package names or versions can be enumerated from this packet.
What supports this
Partially supported- The supply-chain analyst's September 6, 2026 analysis supports tarball-level verification: it reports that stolen npm tokens were used to alter and republish 444 packages across 2,212 versions in under four hours without corresponding GitHub commits. The campaign details remain reported rather than independently verified.
- The moderator's September 6, 2026 synthesis supports the same trust conclusion: clean GitHub history and code review cannot clear a registry tarball if the reported source divergence occurred. It explicitly treats the figures and mechanics as reported claims.
- The operational evidence audit supports execution as the containment boundary, quarantine of the execution environment and downstream artifacts, source-bound provenance checks, and rotation of credentials shown to have been accessible.
- The credential-rotation audit finds insufficient evidence for rotating every reachable credential categorically. It supports default rotation after assessing accessibility while preserving the unresolved exfiltration threshold.
- The affected-version audit identifies an evidence gap: no authoritative npm package-and-version inventory or registry hashes are available for direct matching.
How the Roundtable reached this
Partially supportedThe supply-chain analyst surfaced the reported ChainDrop mutation path: stolen npm publishing tokens allegedly enabled registry tarballs to change without matching GitHub commits.
The decision scout converted that finding into an execution-based containment rule and initially proposed rotating every reachable credential.
The evidence auditor supported quarantine, downstream-artifact isolation and source-bound provenance checks, but found insufficient evidence for an absolute credential-rotation rule and identified the missing authoritative package-and-version inventory. The boundary reviewer agreed with those limits.
A record search found no prior decision to update, so the arbiter selected a new operational record and changed credential rotation from an absolute rule to the default for credentials shown to have been accessible after execution.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 9 candidate signals.
- Linker (AI panel role)Linker evaluated 9 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 20 evidence signals; 12 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 1 prediction and rejected 1 claim.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 15 public/private findings.
- Arbiter (AI panel role)Arbiter produced 9 decision envelopes.
Key disagreement
Scout (AI panel role)
Campaign scale and mechanics remain reported claims, and the discussion did not fully resolve whether exfiltration proof should ever be required before credential rotation.
Arbiter outcome
Arbiter outcome: new decision record. No existing record was available for an update, while the supported execution-based containment position warrants a new operational record with softened credential-rotation wording.
Candidates considered
Considered 9 candidates · opened 1 · 8 not opened (8 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
MissingChainDrop's reported scale and use of stolen npm publishing tokens were not independently verified in this packet.
No authoritative package-and-version list establishes which npm installations require response.
The evidence also leaves the credential threshold unresolved: execution and accessibility support default rotation, but the packet does not justify an unconditional rule covering every merely reachable credential or settle when proof of exfiltration matters.
What evidence is missing
MissingThe packet lacks an authoritative inventory of affected npm package names, versions and registry hashes.
It also lacks independent corroboration of the reported ChainDrop scale and mechanics: 444 packages, 2,212 versions and mutation in under four hours.
Finally, it does not resolve whether confirmed credential exfiltration should ever be required before rotating a credential that was accessible to an executed package.
What would change this
Under reviewAn authoritative affected-package inventory with exact versions and registry hashes would narrow the response from broad investigation to direct matching.
Reliable evidence that a present package never executed would keep the case at exposure assessment rather than trigger execution-based quarantine. Source-bound provenance validating a specific registry tarball would change that artifact's classification.
Evidence that an executed package could not access a credential would remove that credential from the default rotation scope; evidence resolving the role of confirmed exfiltration would further change the rotation threshold.
What to watch next
Under reviewWatch for an authoritative list of affected npm package names, versions and registry hashes; when published, compare it immediately with lockfiles and caches.
Continue reviewing install and CI logs and telemetry for execution indicators; an execution match triggers quarantine of the environment and derived artifacts. Track source-bound provenance for each suspect registry tarball rather than relying on GitHub history.
Reassess credential rotation when evidence clarifies which credentials were accessible or whether confirmed exfiltration is required.
Evidence basis
ChainDrop changes the trust problem by separating the published npm artifact from its source repository. The reported campaign used stolen npm tokens to alter and republish tarballs—444 packages and 2,212 versions in under four hours—withou…
What is genuinely new is the **mutation plane**. ChainDrop reportedly poisoned 444 npm packages across 2,212 versions in under four hours by using stolen npm tokens to download, modify, and republish package tarballs—without corresponding s…
Summary: Active compromise of exposed control planes—not vulnerability volume—sets today’s priority. CISA KEV listings and Huntress/Arctic Wolf reporting make the PaperCut chain the clearest immediate incident risk; TeamCity, Anubis, and th…
Public value history
- 06 Sep 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableMorning roundtableConvened 06 Sep 2026Methodology
How the panel reaches a Public Decision Record.