ChainDrop npm Attack Compromises Hundreds of Packages
A sophisticated software supply chain attack named ChainDrop has infected hundreds of npm packages, including popular caching libraries with millions of weekly downloads. Beginning August 4, 2026, attackers compromised a GitHub account of a keyv package maintainer, injecting malicious code into legitimate repositories. The malware executes credential-stealing payloads targeting developer workstations and CI/CD runners, harvesting npm tokens, GitHub credentials, cloud access keys, SSH keys, and database credentials. Using stolen credentials, the worm self-propagates by compromising additional repositories and publishing poisoned packages with valid provenance attestations. ChainDrop employs Bun runtime for execution, establishes persistence through developer tool configurations, and exfiltrates encrypted data using blockchain-based command-and-control infrastructure. This campaign represents an evolution of the Shai-Hulud npm worm.
Indicators of Compromise
- hash: 00ca0c04d247ef09f2b2acc452029345
- hash: dbb9b09957113463bbeb420c2c4108b5
- hash: 7b0278216ac31ec18eca9eb8bc1c1261a1b26f6c
- hash: ff7ed7a0fa1c43eed01809d076feedbaed464fc7
- hash: 14eb4ce01dd4307759887ff819359b70d7d9ff709ecde039a5abc1aac325b128
- hash: 927387d0cfac1118df4b383decc2ea6ba49c9d2f98b47098bcbcba1efc026e1f
- domain: npm-cache.com
- domain: pypi-get.com
- domain: js-mirror.com
- domain: go.getblock.io
- hash: 35a672cf34b996b91f3e1c28cbf3a05a37e036e4
- hash: f525d52ceb966516686b482d3dc0137028cc6a63
- hash: 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc
- hash: fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb
- hash: 4140f7e17e6f97f83aa3472473e01add
- hash: 7bcf8d9f6834c44450eac145a967d2f2
- hash: 3f3f42d072bd36860ab7bd7fb5e10ac0d22c741c13c89505ccd6ec0ea572eea7
ChainDrop npm Attack Compromises Hundreds of Packages
Description
A sophisticated software supply chain attack named ChainDrop has infected hundreds of npm packages, including popular caching libraries with millions of weekly downloads. Beginning August 4, 2026, attackers compromised a GitHub account of a keyv package maintainer, injecting malicious code into legitimate repositories. The malware executes credential-stealing payloads targeting developer workstations and CI/CD runners, harvesting npm tokens, GitHub credentials, cloud access keys, SSH keys, and database credentials. Using stolen credentials, the worm self-propagates by compromising additional repositories and publishing poisoned packages with valid provenance attestations. ChainDrop employs Bun runtime for execution, establishes persistence through developer tool configurations, and exfiltrates encrypted data using blockchain-based command-and-control infrastructure. This campaign represents an evolution of the Shai-Hulud npm worm.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://op-c.net/blog/chaindrop-npm-supply-chain-attack/"]
- Adversary
- null
- Pulse Id
- 6a7484b807f5882281629fae
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash00ca0c04d247ef09f2b2acc452029345 | — | |
hashdbb9b09957113463bbeb420c2c4108b5 | — | |
hash7b0278216ac31ec18eca9eb8bc1c1261a1b26f6c | — | |
hashff7ed7a0fa1c43eed01809d076feedbaed464fc7 | — | |
hash14eb4ce01dd4307759887ff819359b70d7d9ff709ecde039a5abc1aac325b128 | — | |
hash927387d0cfac1118df4b383decc2ea6ba49c9d2f98b47098bcbcba1efc026e1f | — | |
hash35a672cf34b996b91f3e1c28cbf3a05a37e036e4 | — | |
hashf525d52ceb966516686b482d3dc0137028cc6a63 | — | |
hash9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc | — | |
hashfd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb | — | |
hash4140f7e17e6f97f83aa3472473e01add | — | |
hash7bcf8d9f6834c44450eac145a967d2f2 | — | |
hash3f3f42d072bd36860ab7bd7fb5e10ac0d22c741c13c89505ccd6ec0ea572eea7 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainnpm-cache.com | — | |
domainpypi-get.com | — | |
domainjs-mirror.com | — | |
domaingo.getblock.io | — |
Threat ID: 6a74b929bf8831d539fc6e63
Added to database: 08/06/2026, 16:41:13 UTC
Last updated: 08/06/2026, 20:46:19 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.