Skip to main content

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

0
High
Published: 08/04/2026 (08/04/2026, 23:46:41 UTC)
Source: Microsoft Security Blog

Description

In this article Attack chain overview Mitigation and protection guidance Indicators of compromise (IOC) Microsoft Defender XDR detections Advanced hunting queries Learn more Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting more than 400 packages across multiple unrelated publishers, including packages associated with major enterprise software ecosystems such as keyv, flat-cache, cache-manager, and others. The malicious releases contain a Mini Shai-Hulud variant, a self-propagating credential-stealing worm delivered through a large, heavily obfuscated Bun-based JavaScript payload. The malware typically executes automatically through an npm preinstall lifecycle hook before package installation completes. Once executed, the malware searches developer workstations and continuous integration and continuous delivery (CI/CD) environments for npm, GitHub, cloud, and infrastructure credentials. It uses recovered identities to authenticate to npm, GitHub, Amazon Web Services (AWS), Kubernetes, and HashiCorp Vault, enabling it to enumerate packages, repositories, workflow secrets, cloud parameters, and secret-store values. Collected data is encrypted and transmitted through an attacker-controlled HTTPS endpoint, with GitHub repositories serving as a fallback exfiltration channel. The payload’s most significant capability is automated propagation. After obtaining an npm publishing token, it enumerates packages available to the compromised identity, downloads their latest tarballs, inserts the malware and setup loader, adds a preinstall hook, increments the patch version, and republishes the modified packages. The malware can also use stolen GitHub credentials to inject Claude and Visual Studio Code configuration files into repositories, establishing persistence and creating an additional developer-to-developer infection path. In this blog, we’re sharing our analysis of this supply chain attack, along with protection, detection, amd hunting guidance. Organizations that installed an affected package with lifecycle scripts enabled should treat the associated developer workstation or build runner as potentially compromised. Investigations should prioritize credentials accessible to the affected identity, unauthorized npm releases, unexpected repository or workflow modifications, suspicious cloud and secret-store access, and artifacts produced by affected build systems. Organizations should revoke and rotate exposed credentials from a known-clean environment and rebuild affected systems and downstream artifacts from trusted sources. Attack chain overview The campaign appeared as a rapid sequence of unauthorized patch releases across more than 400 npm packages maintained by otherwise unrelated publishers. Many malicious versions had no corresponding source-code commit, pull request, tag, or legitimate release, indicating that the attackers modified and published package tarballs directly rather than compromising each public source repository. Affected releases typically added a preinstall lifecycle script that launched a malicious file, setup.mjs, contained within the package, which launched the large, obfuscated Bun JavaScript bundle included in the package. Because npm runs preinstall scripts before installation completes, the payload could execute on developer workstations and build runners before application tests or conventional security checks began. After execution, the malware performs the following actions: Determines whether it is running on a developer workstation or in a CI/CD environment. On workstations, it detaches itself to continue after installation; on CI/CD systems, it remains in the active job to access workflow secrets, runner credentials, and OpenID Connect (OIDC) publishing permissions. Both paths could support further package or repository propagation when suitable credentials are found. Collects credentials from local files, environment variables, command-line tools, and GitHub A…

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 18:40:20 UTC

Technical Analysis

Microsoft Threat Intelligence identified a widespread npm supply chain compromise affecting over 400 packages, including those linked to major enterprise ecosystems. The attack uses a Mini Shai-Hulud variant worm delivered via a Bun-based JavaScript payload executed automatically by npm preinstall hooks before package installation completes. The malware collects credentials from local files, environment variables, and command-line tools on developer workstations and CI/CD systems, then authenticates to npm, GitHub, AWS, Kubernetes, and HashiCorp Vault to enumerate and exfiltrate sensitive data. It propagates by obtaining npm publishing tokens, modifying package tarballs to insert malicious code and preinstall hooks, incrementing patch versions, and republishing the packages. Additionally, it injects malicious configuration files into GitHub repositories to establish persistence and enable further infection. The attack chain bypasses conventional security checks by executing early in the package installation process and leverages stolen credentials for lateral movement and propagation.

Potential Impact

The attack compromises developer workstations and CI/CD environments by stealing a wide range of credentials, enabling unauthorized access to npm packages, GitHub repositories, cloud infrastructure, and secret stores. This leads to unauthorized package modifications, data exfiltration, and persistent infection across multiple software supply chains. The self-propagating nature of the worm increases the scale and speed of compromise, potentially affecting numerous downstream consumers of the infected packages. The integrity of software supply chains and cloud environments is severely undermined, posing significant risks to organizations relying on affected npm packages.

Defensive Guidance

Organizations that installed affected npm packages with lifecycle scripts enabled should consider the associated developer workstations and build runners as compromised. Immediate actions include revoking and rotating all exposed credentials from a known-clean environment. Investigations should focus on unauthorized npm releases, unexpected repository or workflow changes, suspicious cloud and secret-store access, and artifacts from affected build systems. Affected systems and downstream artifacts should be rebuilt from trusted sources. Follow Microsoft’s detailed detection, protection, and hunting guidance available in their advisory. No official patch exists for the packages themselves since the compromise involves unauthorized republishing; remediation relies on credential management and rebuilding from clean sources.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.87,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/","fetched":true,"fetchedAt":"2026-08-05T18:39:30.880Z","wordCount":3007}

Threat ID: 6a738364bf8831d53948dfa8

Added to database: 08/05/2026, 18:39:32 UTC

Last enriched: 08/05/2026, 18:40:20 UTC

Last updated: 09/20/2026, 04:04:54 UTC

Views: 254

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses