ChainDrop Worm Hijacks npm Packages to Steal Credentials and Self-Propagate
A critical supply chain attack dubbed 'ChainDrop,' part of the Shai-Hulud worm family, was disclosed by Aikido Security on August 4, 2026, affecting over 434 npm packages including keyv, flat-cache, and file-entry-cache, with combined downloads exceeding 2 billion per month. Attackers compromised GitHub accounts of package maintainers, pushed malicious files directly to repositories, and used legitimate GitHub Actions to publish tainted versions that carried valid provenance signatures. Once a user or CI system installs an affected package, a preinstall script silently downloads the Bun runtime and executes obfuscated malware that harvests credentials from npm, GitHub, AWS, Kubernetes, HashiCorp Vault, Stripe, Slack, and local environment files. Stolen tokens are then used to republish compromised versions to npm and commit malicious code to up to 50 GitHub branches, while hooks injected into VS Code and Claude Code settings ensure the attack re-executes when developers open affected repositories. Exfiltrated data is uploaded to a public GitHub repository, with a blockchain-resolved fallback domain serving as a secondary exfiltration endpoint.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in