Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ChainDrop: The Mini Shai Hulud npm worm's latest wave hits keyv and cacheable

0
Medium
Published: 08/05/2026 (08/05/2026, 08:28:38 UTC)
Source: AlienVault OTX General

Description

The ChainDrop malware campaign involves attackers compromising a GitHub maintainer account for popular Node.js packages keyv, cacheable, flat-cache, and file-entry-cache. Malicious code was pushed to the main branch and automatically published to npm with valid signatures. The payload downloads a Bun runtime to execute obfuscated code that harvests credentials from npm, GitHub, AWS, Kubernetes, and Vault, scans for SSH keys and environment files, and exfiltrates data to attacker-controlled GitHub repositories and Ethereum smart contracts. The malware autonomously uses stolen npm tokens to infect additional packages, making it a self-propagating npm worm. ChainDrop is part of the Shai Hulud family of supply chain attacks previously observed in May 2026.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 12:42:10 UTC

Technical Analysis

Attackers gained control of a GitHub maintainer account managing several widely used Node.js packages (keyv, cacheable, flat-cache, file-entry-cache) with over a billion monthly downloads. They pushed malicious code directly to the main branch, which was automatically published to npm with valid signatures, bypassing typical trust mechanisms. The malicious preinstall script downloads a Bun runtime to run an obfuscated payload that harvests sensitive credentials from multiple platforms including npm, GitHub, AWS, Kubernetes, and Vault. It also scans for SSH keys and environment files to maximize credential theft. Exfiltrated data is sent to attacker-controlled GitHub repositories and Ethereum smart contracts. Using stolen npm tokens, the worm autonomously infects other packages, enabling self-propagation. This campaign, named ChainDrop, continues the Shai Hulud malware family’s supply chain attacks targeting open-source ecosystems.

Potential Impact

This supply chain malware compromises trusted npm packages, potentially affecting any users or systems that install or update these packages. Credential harvesting from multiple cloud and development platforms can lead to broader compromise of developer environments and cloud infrastructure. The autonomous self-propagation using stolen npm tokens increases the risk of widespread infection across the npm ecosystem. Data exfiltration to attacker-controlled repositories and smart contracts indicates potential for ongoing attacker control and monetization. No known exploits in the wild are reported yet, but the scale and automation of the attack pose a significant medium-level threat to the Node.js supply chain.

Defensive Guidance

No official patch or remediation is currently documented. Users and maintainers of affected packages should audit package integrity and GitHub account security. Revoke and rotate any exposed credentials and npm tokens. Monitor for suspicious package updates or preinstall scripts. Consider temporarily avoiding or locking dependencies on the affected packages until further vendor or maintainer advisories are available. Follow updates from package maintainers and security researchers for official fixes or mitigations.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://expel.com/blog/chaindrop-the-mini-shai-hulud-npm-worms-latest-wave-hits-keyv-and-cacheable/"]
Adversary
null
Pulse Id
6a72f4367f010bc9d645f5d1
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainnpm-cache.com
domainpypi-get.com
domainjs-mirror.com

Hash

ValueDescriptionCopy
hash35a672cf34b996b91f3e1c28cbf3a05a37e036e4
hashf525d52ceb966516686b482d3dc0137028cc6a63
hash54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668
hash9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc
hashfd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb
hash4140f7e17e6f97f83aa3472473e01add
hash7bcf8d9f6834c44450eac145a967d2f2
hashf92ee93a0af971a3966bfa8efa9c2625
hashe65b155ce74f3f81fb7d2b5b60f8e62b36e6d69c

Threat ID: 6a72fab9bf8831d53992fddb

Added to database: 08/05/2026, 08:56:25 UTC

Last enriched: 08/05/2026, 12:42:10 UTC

Last updated: 08/06/2026, 01:43:47 UTC

Views: 141

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses