Attackers behind Shai-Hulud compromised the maintainer of the widely used npm library keyv and used a self-propagating worm dubbed CHAINDROP to trojanize the keyv monorepo and spread malicious updates across more than 400 npm packages. The campaign abused npm preinstall hooks for code execution, stole developer credentials from infected machines, and automatically republished malicious package versions anywhere stolen npm tokens had write access, including cases where the tokens bypassed 2FA protections. Packages tied to the keyv ecosystem, including flat-cache, cacheable-request, cacheable, and cache-manager, were identified as part of the downstream exposure, raising broad risk across JavaScript build pipelines and dependent applications.
The malware expanded beyond package tampering by implanting Claude Code and VS Code execution hooks and harvesting secrets tied to AI tooling, cloud environments, GitHub, Kubernetes, Vault, SSH, and npm accounts. Elastic Security Labs reported that the operators used an Ethereum smart contract with fallback mechanisms to dynamically resolve exfiltration infrastructure, underscoring a more resilient and automated supply-chain tradecraft. Published guidance urged organizations to revoke GitHub and npm tokens, review repositories for suspicious commits attributed to "claude", rotate exposed secrets, enable npm 2FA, and upgrade to npm 12+ as defenders assess the blast radius of one of the largest recent npm ecosystem compromises.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On August 5, 2026, Aikido Security reported that the Shai-Hulud/CHAINDROP campaign had reached 1,381 malicious package versions across 444 npm packages. The report showed the worm had spread beyond the initial keyv-related packages into packages maintained by other organizations.
Wiz Research published additional technical findings on the Keyv/Cacheable supply-chain attack, describing expanded credential-theft targets, updated dead-man-switch logic, a new RSA key for exfiltration, and dynamic C2 retrieval from an Ethereum smart contract that was later updated to return only npm-cache[.]com. Wiz also listed compromised package versions including keyv 6.0.0, @cacheable/utils 2.5.1, cache-manager 7.2.10, and cacheable-request 13.0.20, along with related IOCs.
Elastic Security Labs disclosed additional technical details for the CHAINDROP npm supply-chain campaign, including payload and dropper filenames, hashes, C2 and dead-drop domains, and use of an Ethereum smart contract for exfiltration discovery. The report also said the malware could modify GitHub repositories using stolen GitHub App tokens and plant malicious Claude Code and VS Code configuration files across multiple branches.
On August 4, 2026, Elastic Security Labs identified a new Shai-Hulud supply-chain campaign targeting the maintainer of the widely used npm package keyv. The attackers backdoored the keyv monorepo and embedded the self-propagating CHAINDROP worm to execute via npm preinstall hooks.
OX Security reported the first observed delivery of a Shai-Hulud payload through the official Model Context Protocol Registry, via the V.A.P.E MCP server entry. The linked PyPI package was described as clean, but the associated GitHub repository contained malicious Claude Code and VS Code settings files that triggered credential theft when opened or cloned.
The worm used stolen npm credentials to automatically republish malicious versions of packages for which compromised maintainers had write access and could bypass 2FA. Reporting on the incident states that more than 400 unique npm packages were compromised within hours, creating broad downstream exposure across the JavaScript ecosystem.
Microsoft and Socket said the Mini Shai-Hulud npm supply-chain campaign had grown to 2,234 affected package artifacts spanning 444 unique packages while still spreading. The reporting also described the malware as stealing npm, code-hosting, cloud, and CI/CD credentials and reusing stolen publishing access to republish additional packages.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 23 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
16 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcezscaler.com
Open sourceblog.polyswarm.io
Open sourceox.security
Open sourcemalware.news
Open sourcesygnia.co
Open sourceinfosecurity-magazine.com
Open sourceramimac.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.