On August 4, 2026, a self-propagating worm called ChainDrop entered the npm ecosystem through a compromised maintainer account. ChainDrop is a variant of Mini Shai-Hulud linked to TeamPCP.
ChainDrop
ChainDrop is a cross-platform, self-propagating npm supply-chain worm and Mini Shai-Hulud variant first identified in August 2026.
Profile source: Mallory opens in a new tabChainDrop
Family profile
ChainDrop is a cross-platform, self-propagating npm supply-chain worm and Mini Shai-Hulud variant first identified in August 2026. It spread from compromised npm maintainer publishing access by adding malicious preinstall lifecycle logic to otherwise functional packages. Installation or update of an affected dependency executes an obfuscated JavaScript payload on developer workstations and CI/CD runners, including Linux, macOS, and Windows systems.
The malware harvests npm and GitHub credentials, cloud-provider credentials, SSH material, Kubernetes and HashiCorp Vault secrets, environment data, CI/CD secrets, and credentials or configuration associated with AI-assisted development tools. It searches extensive local credential locations and can recover temporary secrets from GitHub Actions runner memory. Collected data is compressed, encrypted, and exfiltrated through attacker-controlled infrastructure; it can also create public repositories under compromised GitHub identities as a fallback exfiltration mechanism.
ChainDrop propagates by validating stolen npm tokens, identifying packages for which the associated account has publishing permission, inserting its loader and payload, adding or replacing lifecycle scripts, incrementing package versions, and republishing trojanized releases. It may use captured GitHub credentials to modify accessible repositories and seed additional execution paths. The malware establishes persistence by modifying project configuration for Visual Studio Code and Claude Code, allowing reinfection when a developer opens a workspace or starts an AI coding session. It dynamically resolves command-and-control and exfiltration infrastructure through an Ethereum smart contract, enabling operators to rotate destinations without updating deployed payloads. More than 400 npm packages were reported compromised during the campaign; reported package and artifact counts varied as tracking continued.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Lateral Movement
- Persistence
Reported operators
Threat actors
2 named in public reportingThe attackers trojanized the monorepo and embedded a self-propagating worm called CHAINDROP that uses stolen npm credentials to automatically backdoor every other package the maintainer had publish rights to.
MITRE ATT&CK
ChainDrop in ATT&CK
62 distinct techniquesTechniques
62 techniquesReporting
Research mentioning ChainDrop
Malicious indexed-btree npm Package Bypasses npm v12 Security | The CyberSec Guru
A counterfeit npm package, indexed-btree, impersonated the legitimate sorted-btree library and embedded malicious logic in BTree.prototype.set() rather than using install-time lifecycle hooks. The payload activated during ordinary application use when a key equal to 100 was inserted and extended/sharedLoad.min.js was present, allowing it to evade npm v12 controls designed to require approval for lifecycle scripts. The obfuscated loader fingerprinted affected hosts and exfiltrated reconnaissance to hard-coded Slack and Telegram endpoints. It used an Ethereum Sepolia testnet smart contract for resilient command-and-control and encrypted second-stage payload delivery, deriving AES keys through X25519/ECDH; it also removed injected code and malicious files to reduce forensic evidence. Checkmarx linked the activity to nine additional removed packages and the earlier mutex-forge package through shared blockchain infrastructure; the associated packages had millions of downloads, and operators reportedly accumulated 109 ETH through the smart contract.
Campagne npm 'btree' : malware caché dans le prototype JS, 2 millions de téléchargements hebdomadaires | CyberVeille
Shai-Hulud: Whoever controls your package registry controls your pipeline - The New Stack
Organizations are adopting dependency cooldowns to prevent build systems from automatically selecting newly published package versions during a defined waiting period. Semgrep deployed a one-week cooldown across Python projects using uv, causing resolution to choose older eligible releases while registries and the community have time to identify and remove malicious packages. Its rollout required an updated uv version, exemptions for internal or urgently needed packages and registries without reliable publication timestamps, and lockfile validation. The control addresses supply-chain campaigns in which compromised maintainer credentials and trusted release pipelines distribute malicious updates, including reported Shai-Hulud-related npm activity. Renovate provides a comparable minimumReleaseAge policy for dependency-update workflows; updates remain pending until they meet the age threshold, while security updates bypass the delay. Effective deployment depends on strict handling of missing release timestamps, immutable dependency pinning, curated registries, short-lived OIDC credentials, restricted CI/CD runner egress, and hardened GitHub Actions workflows so a compromised update or pull request cannot seize build credentials.
How to Roll Out Dependency Cooldowns Org-Wide | Semgrep
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages - Elastic Security Labs
Attackers behind Shai-Hulud compromised the maintainer of the widely used npm library keyv and used a self-propagating worm dubbed CHAINDROP to trojanize the keyv monorepo and spread malicious updates across more than 400 npm packages. The campaign abused npm preinstall hooks for code execution, stole developer credentials from infected machines, and automatically republished malicious package versions anywhere stolen npm tokens had write access, including cases where the tokens bypassed 2FA protections. Packages tied to the keyv ecosystem, including flat-cache, cacheable-request, cacheable, and cache-manager, were identified as part of the downstream exposure, raising broad risk across JavaScript build pipelines and dependent applications. The malware expanded beyond package tampering by implanting Claude Code and VS Code execution hooks and harvesting secrets tied to AI tooling, cloud environments, GitHub, Kubernetes, Vault, SSH, and npm accounts. Elastic Security Labs reported that the operators used an Ethereum smart contract with fallback mechanisms to dynamically resolve exfiltration infrastructure, underscoring a more resilient and automated supply-chain tradecraft. Published guidance urged organizations to revoke GitHub and npm tokens, review repositories for suspicious commits attributed to "claude", rotate exposed secrets, enable npm 2FA, and upgrade to npm 12+ as defenders assess the blast radius of one of the largest recent npm ecosystem compromises.