ChainDrop npm Attack Compromises Hundreds of Packages
A sophisticated software supply chain attack named ChainDrop has infected hundreds of npm packages, including popular caching libraries with millions of weekly downloads. Beginning August 4, 2026, attackers compromised a GitHub account of a keyv package maintainer, injecting malicious code into legitimate repositories. The malware executes credential-stealing payloads targeting developer workstations and CI/CD runners, harvesting npm tokens, GitHub credentials, cloud access keys, SSH keys, and database credentials. Using stolen credentials, the worm self-propagates by compromising additional repositories and publishing poisoned packages with valid provenance attestations. ChainDrop employs Bun runtime for execution, establishes persistence through developer tool configurations, and exfiltrates encrypted data using blockchain-based command-and-control infrastructure. This campaign represents an evolution of the Shai-Hulud npm worm.
AI Analysis
Technical Summary
Beginning August 4, 2026, attackers compromised a GitHub account of a maintainer for the keyv npm package, injecting malicious code into legitimate repositories. The ChainDrop malware executes credential-stealing payloads that harvest npm tokens, GitHub credentials, cloud access keys, SSH keys, and database credentials from developer workstations and CI/CD runners. Using stolen credentials, the worm self-propagates by compromising additional repositories and publishing poisoned npm packages with valid provenance attestations. ChainDrop uses the Bun runtime for execution, persists through developer tool configurations, and exfiltrates encrypted data via blockchain-based command-and-control infrastructure. This campaign represents an evolution of the Shai-Hulud npm worm and has infected hundreds of npm packages, including popular caching libraries with millions of weekly downloads.
Potential Impact
The attack compromises developer credentials and access tokens, potentially allowing attackers to access sensitive cloud resources, source code repositories, and databases. The self-propagating worm can spread widely across the npm ecosystem by publishing poisoned packages that appear legitimate due to valid provenance attestations. This threatens the integrity of software supply chains and developer infrastructure, increasing the risk of widespread credential theft and unauthorized access to critical development and deployment environments.
Mitigation Recommendations
No official patch or remediation is stated in the provided data. Patch status is not yet confirmed — check the vendor advisory and npm security announcements for current remediation guidance. Developers should audit their npm packages and GitHub repositories for unauthorized changes, revoke and rotate compromised credentials and tokens, and monitor for suspicious activity related to the identified malicious domains and file hashes. Consider isolating build environments and reviewing CI/CD pipeline security configurations to limit exposure. Follow updates from trusted security sources for further mitigation recommendations.
Indicators of Compromise
- hash: 00ca0c04d247ef09f2b2acc452029345
- hash: dbb9b09957113463bbeb420c2c4108b5
- hash: 7b0278216ac31ec18eca9eb8bc1c1261a1b26f6c
- hash: ff7ed7a0fa1c43eed01809d076feedbaed464fc7
- hash: 14eb4ce01dd4307759887ff819359b70d7d9ff709ecde039a5abc1aac325b128
- hash: 927387d0cfac1118df4b383decc2ea6ba49c9d2f98b47098bcbcba1efc026e1f
- domain: npm-cache.com
- domain: pypi-get.com
- domain: js-mirror.com
- domain: go.getblock.io
- hash: 35a672cf34b996b91f3e1c28cbf3a05a37e036e4
- hash: f525d52ceb966516686b482d3dc0137028cc6a63
- hash: 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc
- hash: fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb
- hash: 4140f7e17e6f97f83aa3472473e01add
- hash: 7bcf8d9f6834c44450eac145a967d2f2
- hash: 3f3f42d072bd36860ab7bd7fb5e10ac0d22c741c13c89505ccd6ec0ea572eea7
ChainDrop npm Attack Compromises Hundreds of Packages
Description
A sophisticated software supply chain attack named ChainDrop has infected hundreds of npm packages, including popular caching libraries with millions of weekly downloads. Beginning August 4, 2026, attackers compromised a GitHub account of a keyv package maintainer, injecting malicious code into legitimate repositories. The malware executes credential-stealing payloads targeting developer workstations and CI/CD runners, harvesting npm tokens, GitHub credentials, cloud access keys, SSH keys, and database credentials. Using stolen credentials, the worm self-propagates by compromising additional repositories and publishing poisoned packages with valid provenance attestations. ChainDrop employs Bun runtime for execution, establishes persistence through developer tool configurations, and exfiltrates encrypted data using blockchain-based command-and-control infrastructure. This campaign represents an evolution of the Shai-Hulud npm worm.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Beginning August 4, 2026, attackers compromised a GitHub account of a maintainer for the keyv npm package, injecting malicious code into legitimate repositories. The ChainDrop malware executes credential-stealing payloads that harvest npm tokens, GitHub credentials, cloud access keys, SSH keys, and database credentials from developer workstations and CI/CD runners. Using stolen credentials, the worm self-propagates by compromising additional repositories and publishing poisoned npm packages with valid provenance attestations. ChainDrop uses the Bun runtime for execution, persists through developer tool configurations, and exfiltrates encrypted data via blockchain-based command-and-control infrastructure. This campaign represents an evolution of the Shai-Hulud npm worm and has infected hundreds of npm packages, including popular caching libraries with millions of weekly downloads.
Potential Impact
The attack compromises developer credentials and access tokens, potentially allowing attackers to access sensitive cloud resources, source code repositories, and databases. The self-propagating worm can spread widely across the npm ecosystem by publishing poisoned packages that appear legitimate due to valid provenance attestations. This threatens the integrity of software supply chains and developer infrastructure, increasing the risk of widespread credential theft and unauthorized access to critical development and deployment environments.
Defensive Guidance
No official patch or remediation is stated in the provided data. Patch status is not yet confirmed — check the vendor advisory and npm security announcements for current remediation guidance. Developers should audit their npm packages and GitHub repositories for unauthorized changes, revoke and rotate compromised credentials and tokens, and monitor for suspicious activity related to the identified malicious domains and file hashes. Consider isolating build environments and reviewing CI/CD pipeline security configurations to limit exposure. Follow updates from trusted security sources for further mitigation recommendations.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://op-c.net/blog/chaindrop-npm-supply-chain-attack/"]
- Pulse Id
- 6a7484b807f5882281629fae
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash00ca0c04d247ef09f2b2acc452029345 | — | |
hashdbb9b09957113463bbeb420c2c4108b5 | — | |
hash7b0278216ac31ec18eca9eb8bc1c1261a1b26f6c | — | |
hashff7ed7a0fa1c43eed01809d076feedbaed464fc7 | — | |
hash14eb4ce01dd4307759887ff819359b70d7d9ff709ecde039a5abc1aac325b128 | — | |
hash927387d0cfac1118df4b383decc2ea6ba49c9d2f98b47098bcbcba1efc026e1f | — | |
hash35a672cf34b996b91f3e1c28cbf3a05a37e036e4 | — | |
hashf525d52ceb966516686b482d3dc0137028cc6a63 | — | |
hash9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc | — | |
hashfd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb | — | |
hash4140f7e17e6f97f83aa3472473e01add | — | |
hash7bcf8d9f6834c44450eac145a967d2f2 | — | |
hash3f3f42d072bd36860ab7bd7fb5e10ac0d22c741c13c89505ccd6ec0ea572eea7 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainnpm-cache.com | — | |
domainpypi-get.com | — | |
domainjs-mirror.com | — | |
domaingo.getblock.io | — |
Threat ID: 6a74b929bf8831d539fc6e63
Added to database: 08/06/2026, 16:41:13 UTC
Last enriched: 08/07/2026, 04:49:02 UTC
Last updated: 09/19/2026, 22:19:28 UTC
Views: 178
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.