Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ChainDrop npm Attack Compromises Hundreds of Packages

0
Medium
Published: 08/06/2026 (08/06/2026, 12:57:28 UTC)
Source: AlienVault OTX General

Description

A sophisticated software supply chain attack named ChainDrop has infected hundreds of npm packages, including popular caching libraries with millions of weekly downloads. Beginning August 4, 2026, attackers compromised a GitHub account of a keyv package maintainer, injecting malicious code into legitimate repositories. The malware executes credential-stealing payloads targeting developer workstations and CI/CD runners, harvesting npm tokens, GitHub credentials, cloud access keys, SSH keys, and database credentials. Using stolen credentials, the worm self-propagates by compromising additional repositories and publishing poisoned packages with valid provenance attestations. ChainDrop employs Bun runtime for execution, establishes persistence through developer tool configurations, and exfiltrates encrypted data using blockchain-based command-and-control infrastructure. This campaign represents an evolution of the Shai-Hulud npm worm.

Technical Details

Author
AlienVault
Tlp
white
References
["https://op-c.net/blog/chaindrop-npm-supply-chain-attack/"]
Adversary
null
Pulse Id
6a7484b807f5882281629fae
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash00ca0c04d247ef09f2b2acc452029345
hashdbb9b09957113463bbeb420c2c4108b5
hash7b0278216ac31ec18eca9eb8bc1c1261a1b26f6c
hashff7ed7a0fa1c43eed01809d076feedbaed464fc7
hash14eb4ce01dd4307759887ff819359b70d7d9ff709ecde039a5abc1aac325b128
hash927387d0cfac1118df4b383decc2ea6ba49c9d2f98b47098bcbcba1efc026e1f
hash35a672cf34b996b91f3e1c28cbf3a05a37e036e4
hashf525d52ceb966516686b482d3dc0137028cc6a63
hash9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc
hashfd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb
hash4140f7e17e6f97f83aa3472473e01add
hash7bcf8d9f6834c44450eac145a967d2f2
hash3f3f42d072bd36860ab7bd7fb5e10ac0d22c741c13c89505ccd6ec0ea572eea7

Domain

ValueDescriptionCopy
domainnpm-cache.com
domainpypi-get.com
domainjs-mirror.com
domaingo.getblock.io

Threat ID: 6a74b929bf8831d539fc6e63

Added to database: 08/06/2026, 16:41:13 UTC

Last updated: 08/06/2026, 20:46:19 UTC

Views: 19

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses