A self-propagating npm supply-chain attack dubbed ChainDrop has spread through compromised package releases, with malicious versions using preinstall scripts to execute obfuscated files such as setup.mjs and math_init.js, download a runtime, and launch a second-stage payload. Researchers said the campaign hit many unrelated maintainer scopes in a short period, indicating automated propagation through stolen maintainer credentials or tokens, and described the malware as a CI/CD credential harvester that uses Bun-loaded components and Ethereum dead-drop command-and-control.
StepSecurity said its OSS Security Feed flagged dozens of npm packages as critical during the outbreak and warned that the published list may be incomplete. The broader feed also highlighted recurring npm ecosystem risks including typosquatting, dropped provenance, repository mismatches, and install-time binary downloads, including a critical case where free-email-domains v1.9.15 fetched content from the typosquatted domain hubspotusercontent40.net during postinstall. Defenders were urged to treat any environment that installed affected versions as compromised, rotate secrets, roll back to known-good releases, and inspect developer endpoints, CI runners, and package caches for persistence.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
Researchers reported that ChainDrop exfiltrated stolen data to a public GitHub repository described as "Shai-Hulud: Here We Go Again" and to the domain npm-cache[.]com, which Wiz identified as a reliable indicator of compromise. The update also warned that any workstation or CI/CD runner that installed an infected package should be treated as fully compromised.
CERT-SE published a security notice warning that the self-replicating Chaindrop malware was spreading through the JavaScript and npm ecosystem and affecting more than 400 packages. The advisory told organizations to investigate possible exposure, avoid running npm install or npm update until maintainers confirm releases are clean, and rotate secrets in affected environments.
Microsoft Threat Intelligence reported that ChainDrop republished malicious npm packages by modifying package tarballs directly, often without matching source commits, and used stolen GitHub credentials to inject Claude and Visual Studio Code configuration files into repositories for persistence and secondary spread. The report also documented HTTPS and GitHub-based exfiltration paths and warned that packages published through trusted GitHub Actions workflows could still carry valid provenance.
Expel reported that the ChainDrop payload belongs to the Mini Shai Hulud/Shai Hulud npm worm family. The report said the same malware lineage had previously affected TanStack, Mistral AI, and OpenSearch packages in May 2026, adding a new attribution link for the campaign.
Researchers reported that after compromising the Keyv maintainer's GitHub account, the attacker pushed malicious files to affected projects' main branches and generated poisoned npm releases through legitimate GitHub Actions workflows. As a result, the malicious packages carried valid provenance information despite containing the preinstall dropper and infostealer payloads.
Reporting on the ChainDrop npm supply-chain campaign said the compromise had affected 2,212 projects and 444 victims. The update also highlighted heavily downloaded compromised packages including keyv, flat-cache, and file-entry-cache, indicating broader downstream impact than previously documented.
On August 4, 2026, attackers compromised the GitHub account of the maintainer behind keyv and related caching packages, then pushed malicious releases with a preinstall dropper and credential-stealing payload. By 13:20 CEST, researchers had confirmed at least 868 compromised packages spanning 1,381 versions, marking a major escalation of the ongoing npm worm campaign.
Between approximately 09:50 and 10:50 UTC on 2026-08-04, StepSecurity's OSS Security Feed flagged dozens of npm package releases as critical and identified them as compromised. The affected versions spanned many unrelated maintainer scopes, indicating a rapidly spreading campaign.
Semgrep reported that the earliest known malicious ChainDrop package release was keyv@6.0.0 at 09:35:00Z, marking the first observed publication in the npm worm campaign. The release used the same preinstall-based loader pattern later seen across the broader compromise wave.
After the ChainDrop compromise, keyv version 6.0.0 was restored with legitimate code. The restored release was published using npm Trusted Publishers and included SLSA provenance protections.
StepSecurity reported that ChainDrop's apparent objective was to steal CI/CD-related secrets, including npm tokens, cloud credentials, SSH keys, and other CI secrets. The investigation also found the malware used an Ethereum dead-drop mechanism for command-and-control.
The breadth of compromised packages across unrelated maintainer scopes led investigators to assess the propagation as likely automated, potentially using stolen maintainer credentials or tokens. They also said they were analyzing the payload, command-and-control infrastructure, and propagation mechanism while coordinating with npm and affected maintainers.
StepSecurity reported an active npm ecosystem incident involving a self-propagating worm dubbed ChainDrop. The compromised releases added obfuscated files such as setup.mjs and math_init.js, executed automatically via preinstall scripts, downloaded a runtime, and launched a second-stage payload.
StepSecurity's OSS security feed assessed free-email-domains v1.9.15 as a critical risk after finding a postinstall script that automatically fetched content from the typosquatted domain hubspotusercontent40.net and wrote it into domains.json. The review said this created a supply-chain attack path that could enable payload delivery, backdoor injection, metadata exfiltration, or victim-specific targeting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
16 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcexakep.ru
Open sourcecert.se
Open sourcesecurityweek.com
Open sourcesemgrep.dev
Open sourcecyberveille.ch
Open sourcedocs.npmjs.com
Open sourceapp.stepsecurity.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.