Skip to content

ChainDrop

ChainDrop is a cross-platform, self-propagating npm supply-chain worm and Mini Shai-Hulud variant first identified in August 2026.

Profile source: Mallory opens in a new tab

ChainDrop

Family profile

ChainDrop is a cross-platform, self-propagating npm supply-chain worm and Mini Shai-Hulud variant first identified in August 2026. It spread from compromised npm maintainer publishing access by adding malicious preinstall lifecycle logic to otherwise functional packages. Installation or update of an affected dependency executes an obfuscated JavaScript payload on developer workstations and CI/CD runners, including Linux, macOS, and Windows systems.

The malware harvests npm and GitHub credentials, cloud-provider credentials, SSH material, Kubernetes and HashiCorp Vault secrets, environment data, CI/CD secrets, and credentials or configuration associated with AI-assisted development tools. It searches extensive local credential locations and can recover temporary secrets from GitHub Actions runner memory. Collected data is compressed, encrypted, and exfiltrated through attacker-controlled infrastructure; it can also create public repositories under compromised GitHub identities as a fallback exfiltration mechanism.

ChainDrop propagates by validating stolen npm tokens, identifying packages for which the associated account has publishing permission, inserting its loader and payload, adding or replacing lifecycle scripts, incrementing package versions, and republishing trojanized releases. It may use captured GitHub credentials to modify accessible repositories and seed additional execution paths. The malware establishes persistence by modifying project configuration for Visual Studio Code and Claude Code, allowing reinfection when a developer opens a workspace or starts an AI coding session. It dynamically resolves command-and-control and exfiltration infrastructure through an Ethereum smart contract, enabling operators to rotate destinations without updating deployed payloads. More than 400 npm packages were reported compromised during the campaign; reported package and artifact counts varied as tracking continued.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence

Reported operators

Threat actors

2 named in public reporting
TeamPCP

On August 4, 2026, a self-propagating worm called ChainDrop entered the npm ecosystem through a compromised maintainer account. ChainDrop is a variant of Mini Shai-Hulud linked to TeamPCP.

Shai-Hulud

The attackers trojanized the monorepo and embedded a self-propagating worm called CHAINDROP that uses stolen npm credentials to automatically backdoor every other package the maintainer had publish rights to.

MITRE ATT&CK

ChainDrop in ATT&CK

62 distinct techniques

Techniques

62 techniques
T1552 Unsecured Credentials T1195.002 Compromise Software Supply Chain T1565.001 Stored Data Manipulation T1552.005 Cloud Instance Metadata API T1573.002 Asymmetric Cryptography T1027 Obfuscated Files or Information T1555 Credentials from Password Stores T1546 Event Triggered Execution T1552.004 Private Keys T1078 Valid Accounts T1105 Ingress Tool Transfer T1102.002 Bidirectional Communication T1059.007 JavaScript T1568.002 Domain Generation Algorithms T1560 Archive Collected Data T1070.004 File Deletion T1102 Web Service T1055 Process Injection T1059.006 Python T1649 Steal or Forge Authentication Certificates T1574.006 Dynamic Linker Hijacking T1195 Supply Chain Compromise T1568 Dynamic Resolution T1041 Exfiltration Over C2 Channel T1008 Fallback Channels T1078.004 Cloud Accounts T1003 OS Credential Dumping T1552.001 Credentials In Files T1552.003 Shell History T1528 Steal Application Access Token T1526 Cloud Service Discovery T1204.002 Malicious File T1195.001 Compromise Software Dependencies and Development Tools T1059 Command and Scripting Interpreter T1574 Hijack Execution Flow T1070 Indicator Removal T1567.001 Exfiltration to Code Repository T1497.001 System Checks T1071 Application Layer Protocol T1083 File and Directory Discovery T1567 Exfiltration Over Web Service T1518 Software Discovery T1059.004 Unix Shell T1543.002 Systemd Service T1543.001 Launch Agent T1543 Create or Modify System Process T1001 Data Obfuscation T1053 Scheduled Task/Job T1570 Lateral Tool Transfer T1583.001 Domains T1213 Data from Information Repositories T1588.004 Digital Certificates T1567.002 Exfiltration to Cloud Storage T1071.001 Web Protocols T1539 Steal Web Session Cookie T1574.007 Path Interception by PATH Environment Variable T1119 Automated Collection T1055.009 Proc Memory T1555.003 Credentials from Web Browsers T1199 Trusted Relationship T1078.001 Default Accounts T1102.001 Dead Drop Resolver

Reporting

Research mentioning ChainDrop

Sep 20
Thecybersecguru

Malicious indexed-btree npm Package Bypasses npm v12 Security | The CyberSec Guru

A counterfeit npm package, indexed-btree, impersonated the legitimate sorted-btree library and embedded malicious logic in BTree.prototype.set() rather than using install-time lifecycle hooks. The payload activated during ordinary application use when a key equal to 100 was inserted and extended/sharedLoad.min.js was present, allowing it to evade npm v12 controls designed to require approval for lifecycle scripts. The obfuscated loader fingerprinted affected hosts and exfiltrated reconnaissance to hard-coded Slack and Telegram endpoints. It used an Ethereum Sepolia testnet smart contract for resilient command-and-control and encrypted second-stage payload delivery, deriving AES keys through X25519/ECDH; it also removed injected code and malicious files to reduce forensic evidence. Checkmarx linked the activity to nine additional removed packages and the earlier mutex-forge package through shared blockchain infrastructure; the associated packages had millions of downloads, and operators reportedly accumulated 109 ETH through the smart contract.

Sep 19
Cyberveille

Campagne npm 'btree' : malware caché dans le prototype JS, 2 millions de téléchargements hebdomadaires | CyberVeille

Aug 31
Thenewstack

Shai-Hulud: Whoever controls your package registry controls your pipeline - The New Stack

Organizations are adopting dependency cooldowns to prevent build systems from automatically selecting newly published package versions during a defined waiting period. Semgrep deployed a one-week cooldown across Python projects using uv, causing resolution to choose older eligible releases while registries and the community have time to identify and remove malicious packages. Its rollout required an updated uv version, exemptions for internal or urgently needed packages and registries without reliable publication timestamps, and lockfile validation. The control addresses supply-chain campaigns in which compromised maintainer credentials and trusted release pipelines distribute malicious updates, including reported Shai-Hulud-related npm activity. Renovate provides a comparable minimumReleaseAge policy for dependency-update workflows; updates remain pending until they meet the age threshold, while security updates bypass the delay. Effective deployment depends on strict handling of missing release timestamps, immutable dependency pinning, curated registries, short-lived OIDC credentials, restricted CI/CD runner egress, and hardened GitHub Actions workflows so a compromised update or pull request cannot seize build credentials.

Aug 31
Semgrep

How to Roll Out Dependency Cooldowns Org-Wide | Semgrep

Aug 5
Elastic Security Labs

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages - Elastic Security Labs

Attackers behind Shai-Hulud compromised the maintainer of the widely used npm library keyv and used a self-propagating worm dubbed CHAINDROP to trojanize the keyv monorepo and spread malicious updates across more than 400 npm packages. The campaign abused npm preinstall hooks for code execution, stole developer credentials from infected machines, and automatically republished malicious package versions anywhere stolen npm tokens had write access, including cases where the tokens bypassed 2FA protections. Packages tied to the keyv ecosystem, including flat-cache, cacheable-request, cacheable, and cache-manager, were identified as part of the downstream exposure, raising broad risk across JavaScript build pipelines and dependent applications. The malware expanded beyond package tampering by implanting Claude Code and VS Code execution hooks and harvesting secrets tied to AI tooling, cloud environments, GitHub, Kubernetes, Vault, SSH, and npm accounts. Elastic Security Labs reported that the operators used an Ethereum smart contract with fallback mechanisms to dynamically resolve exfiltration infrastructure, underscoring a more resilient and automated supply-chain tradecraft. Published guidance urged organizations to revoke GitHub and npm tokens, review repositories for suspicious commits attributed to "claude", rotate exposed secrets, enable npm 2FA, and upgrade to npm 12+ as defenders assess the blast radius of one of the largest recent npm ecosystem compromises.

Aug 5
Malware News

Shai-Hulud Returns: When Software Trust Becomes the Attack Surface - Malware Analysis - Malware Analysis, News and Indicators

Aug 5
Sygnia

Shai-Hulud Returns: When Software Trust Becomes the Attack Surface

Oct 14
Docs Renovatebot

Minimum Release Age - Renovate Docs

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.