A self-propagating npm supply-chain attack dubbed ChainDrop has spread through compromised package releases, with malicious versions using preinstall scripts to execute obfuscated files such as setup.mjs and math_init.js, download a runtime, and launch a second-stage payload. Researchers said the campaign hit many unrelated maintainer scopes in a short period, indicating automated propagation through stolen maintainer credentials or tokens, and described the malware as a CI/CD credential harvester that uses Bun-loaded components and Ethereum dead-drop command-and-control.
StepSecurity said its OSS Security Feed flagged dozens of npm packages as critical during the outbreak and warned that the published list may be incomplete. The broader feed also highlighted recurring npm ecosystem risks including typosquatting, dropped provenance, repository mismatches, and install-time binary downloads, including a critical case where free-email-domains v1.9.15 fetched content from the typosquatted domain hubspotusercontent40.net during postinstall. Defenders were urged to treat any environment that installed affected versions as compromised, rotate secrets, roll back to known-good releases, and inspect developer endpoints, CI runners, and package caches for persistence.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
Gurucul Threat Research published detection guidance for ChainDrop that included additional indicators of compromise beyond previously documented ones, including the domains pypi-get.com and js-mirror.com, the URL https://npm-cache.com:443/router, and three SHA-256 hashes. The report also reiterated that the worm used compromised maintainer accounts and harvested secrets to propagate across developer and CI/CD environments.
Researchers reported that ChainDrop exfiltrated stolen data to a public GitHub repository described as "Shai-Hulud: Here We Go Again" and to the domain npm-cache[.]com, which Wiz identified as a reliable indicator of compromise. The update also warned that any workstation or CI/CD runner that installed an infected package should be treated as fully compromised.
CERT-SE published a security notice warning that the self-replicating Chaindrop malware was spreading through the JavaScript and npm ecosystem and affecting more than 400 packages. The advisory told organizations to investigate possible exposure, avoid running npm install or npm update until maintainers confirm releases are clean, and rotate secrets in affected environments.
Unit 42 reported that ChainDrop's Ethereum smart-contract-based command-and-control infrastructure rotated its active domain on August 4, 2026, switching from npm-cache[.]com to awqhnjewqjkl[.]icu. The finding showed the worm's operators could silently change live C2 endpoints without updating the malware itself.
Microsoft Threat Intelligence reported that ChainDrop republished malicious npm packages by modifying package tarballs directly, often without matching source commits, and used stolen GitHub credentials to inject Claude and Visual Studio Code configuration files into repositories for persistence and secondary spread. The report also documented HTTPS and GitHub-based exfiltration paths and warned that packages published through trusted GitHub Actions workflows could still carry valid provenance.
Expel reported that the ChainDrop payload belongs to the Mini Shai Hulud/Shai Hulud npm worm family. The report said the same malware lineage had previously affected TanStack, Mistral AI, and OpenSearch packages in May 2026, adding a new attribution link for the campaign.
Researchers reported that after compromising the Keyv maintainer's GitHub account, the attacker pushed malicious files to affected projects' main branches and generated poisoned npm releases through legitimate GitHub Actions workflows. As a result, the malicious packages carried valid provenance information despite containing the preinstall dropper and infostealer payloads.
Reporting on the ChainDrop npm supply-chain campaign said the compromise had affected 2,212 projects and 444 victims. The update also highlighted heavily downloaded compromised packages including keyv, flat-cache, and file-entry-cache, indicating broader downstream impact than previously documented.
On August 4, 2026, attackers compromised the GitHub account of the maintainer behind keyv and related caching packages, then pushed malicious releases with a preinstall dropper and credential-stealing payload. By 13:20 CEST, researchers had confirmed at least 868 compromised packages spanning 1,381 versions, marking a major escalation of the ongoing npm worm campaign.
Between approximately 09:50 and 10:50 UTC on 2026-08-04, StepSecurity's OSS Security Feed flagged dozens of npm package releases as critical and identified them as compromised. The affected versions spanned many unrelated maintainer scopes, indicating a rapidly spreading campaign.
Semgrep reported that the earliest known malicious ChainDrop package release was keyv@6.0.0 at 09:35:00Z, marking the first observed publication in the npm worm campaign. The release used the same preinstall-based loader pattern later seen across the broader compromise wave.
In May 2026, TeamPCP published the source code for the Shai-Hulud worm in a GitHub repository. Researchers said the repository was quickly taken down, but copies were likely made and the leak enabled new variants and follow-on attacks against developers.
After the ChainDrop compromise, keyv version 6.0.0 was restored with legitimate code. The restored release was published using npm Trusted Publishers and included SLSA provenance protections.
StepSecurity reported that ChainDrop's apparent objective was to steal CI/CD-related secrets, including npm tokens, cloud credentials, SSH keys, and other CI secrets. The investigation also found the malware used an Ethereum dead-drop mechanism for command-and-control.
The breadth of compromised packages across unrelated maintainer scopes led investigators to assess the propagation as likely automated, potentially using stolen maintainer credentials or tokens. They also said they were analyzing the payload, command-and-control infrastructure, and propagation mechanism while coordinating with npm and affected maintainers.
StepSecurity reported an active npm ecosystem incident involving a self-propagating worm dubbed ChainDrop. The compromised releases added obfuscated files such as setup.mjs and math_init.js, executed automatically via preinstall scripts, downloaded a runtime, and launched a second-stage payload.
StepSecurity's OSS security feed assessed free-email-domains v1.9.15 as a critical risk after finding a postinstall script that automatically fetched content from the typosquatted domain hubspotusercontent40.net and wrote it into domains.json. The review said this created a supply-chain attack path that could enable payload delivery, backdoor injection, metadata exfiltration, or victim-specific targeting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
19 references tracked. Mallory keeps watching after this page renders.
unit42.paloaltonetworks.com
Open sourcecommunity.gurucul.com
Open sourceitpro.com
Open sourceacn.gov.it
Open sourcesemgrep.dev
Open sourcecyberveille.ch
Open sourcedocs.npmjs.com
Open sourceapp.stepsecurity.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.