Inside a Self-Propagating npm Worm
ChainDrop is a self-propagating npm worm that infected over 400 widely used packages, including popular ones like keyv and cacheable-request. It steals sensitive developer credentials such as cloud credentials, npm and GitHub tokens, SSH keys, and extracts temporary credentials from GitHub Actions runner memory. The worm uses stolen npm publishing tokens to infect additional packages while preserving their legitimate functionality. Persistence is maintained through VS Code and Claude Code configurations. ChainDrop employs blockchain-based command-and-control (C2) infrastructure via Ethereum smart contracts, allowing silent reconfiguration of C2 without updating deployed instances. It uses multiple layers of obfuscation and encryption, exfiltrates data through encrypted channels, and publishes stolen tokens in public commit messages.
AI Analysis
Technical Summary
ChainDrop is a sophisticated self-propagating malware targeting the npm ecosystem by infecting over 400 packages downloaded hundreds of millions of times weekly. It steals a broad range of developer credentials, including cloud credentials, npm and GitHub tokens, SSH keys, and temporary GitHub Actions runner credentials. The worm leverages stolen npm publishing tokens to propagate by injecting malicious code into additional packages while maintaining their legitimate functionality to avoid detection. Attackers maintain persistence through configurations in VS Code and Claude Code. The malware uses Ethereum smart contracts for blockchain-based command-and-control, enabling the operator to silently update C2 infrastructure via Ethereum transactions without redeploying malware instances. ChainDrop employs three layers of obfuscation and encryption to evade detection, exfiltrates data over encrypted channels, and publicly exposes stolen tokens in commit messages to further its attack chain.
Potential Impact
The infection compromises developer and cloud credentials, including npm and GitHub tokens and SSH keys, potentially allowing attackers to access and manipulate source code repositories, cloud resources, and developer environments. The worm's ability to propagate through npm packages risks widespread supply chain contamination. Persistence mechanisms and blockchain-based C2 infrastructure complicate detection and remediation. The exposure of stolen tokens in public commit messages can lead to further compromise and unauthorized access. This threat undermines the integrity of software supply chains and developer trust.
Mitigation Recommendations
No official patch or remediation is indicated in the provided data. Since this is a malware campaign exploiting compromised npm packages, remediation involves identifying and removing infected packages from projects and build environments, revoking and rotating exposed credentials (npm tokens, GitHub tokens, SSH keys, cloud credentials), and auditing developer environments for persistence mechanisms such as malicious VS Code and Claude Code configurations. Monitoring for suspicious Ethereum smart contract activity related to C2 may assist in detection. Users should consult vendor advisories and trusted security sources for updated guidance. Patch status is not yet confirmed — check vendor advisories for current remediation guidance.
Indicators of Compromise
- hash: d30b4ea6f68456672f5abb35e9dcf7d54226372b66e9d60a7ee26b7a52568e74
- domain: npm-cache.com
- domain: pypi-get.com
- domain: js-mirror.com
- hash: 35a672cf34b996b91f3e1c28cbf3a05a37e036e4
- hash: f525d52ceb966516686b482d3dc0137028cc6a63
- hash: 54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668
- hash: 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc
- hash: fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb
- url: https://npm-cache.com:443/router
- hash: 4140f7e17e6f97f83aa3472473e01add
- hash: 7bcf8d9f6834c44450eac145a967d2f2
- hash: f92ee93a0af971a3966bfa8efa9c2625
- hash: e65b155ce74f3f81fb7d2b5b60f8e62b36e6d69c
- domain: awqhnjewqjkl.icu
- hash: b27b82afa5f15512f3856e549fb83d873fd0049759a4b62ce64c8d7d4dc2c678
- url: http://awqhnjewqjkl.icu/cdn-cgi/rum
Inside a Self-Propagating npm Worm
Description
ChainDrop is a self-propagating npm worm that infected over 400 widely used packages, including popular ones like keyv and cacheable-request. It steals sensitive developer credentials such as cloud credentials, npm and GitHub tokens, SSH keys, and extracts temporary credentials from GitHub Actions runner memory. The worm uses stolen npm publishing tokens to infect additional packages while preserving their legitimate functionality. Persistence is maintained through VS Code and Claude Code configurations. ChainDrop employs blockchain-based command-and-control (C2) infrastructure via Ethereum smart contracts, allowing silent reconfiguration of C2 without updating deployed instances. It uses multiple layers of obfuscation and encryption, exfiltrates data through encrypted channels, and publishes stolen tokens in public commit messages.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
ChainDrop is a sophisticated self-propagating malware targeting the npm ecosystem by infecting over 400 packages downloaded hundreds of millions of times weekly. It steals a broad range of developer credentials, including cloud credentials, npm and GitHub tokens, SSH keys, and temporary GitHub Actions runner credentials. The worm leverages stolen npm publishing tokens to propagate by injecting malicious code into additional packages while maintaining their legitimate functionality to avoid detection. Attackers maintain persistence through configurations in VS Code and Claude Code. The malware uses Ethereum smart contracts for blockchain-based command-and-control, enabling the operator to silently update C2 infrastructure via Ethereum transactions without redeploying malware instances. ChainDrop employs three layers of obfuscation and encryption to evade detection, exfiltrates data over encrypted channels, and publicly exposes stolen tokens in commit messages to further its attack chain.
Potential Impact
The infection compromises developer and cloud credentials, including npm and GitHub tokens and SSH keys, potentially allowing attackers to access and manipulate source code repositories, cloud resources, and developer environments. The worm's ability to propagate through npm packages risks widespread supply chain contamination. Persistence mechanisms and blockchain-based C2 infrastructure complicate detection and remediation. The exposure of stolen tokens in public commit messages can lead to further compromise and unauthorized access. This threat undermines the integrity of software supply chains and developer trust.
Defensive Guidance
No official patch or remediation is indicated in the provided data. Since this is a malware campaign exploiting compromised npm packages, remediation involves identifying and removing infected packages from projects and build environments, revoking and rotating exposed credentials (npm tokens, GitHub tokens, SSH keys, cloud credentials), and auditing developer environments for persistence mechanisms such as malicious VS Code and Claude Code configurations. Monitoring for suspicious Ethereum smart contract activity related to C2 may assist in detection. Users should consult vendor advisories and trusted security sources for updated guidance. Patch status is not yet confirmed — check vendor advisories for current remediation guidance.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/"]
- Adversary
- null
- Pulse Id
- 6a75b2f415506d0a2374398b
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hashd30b4ea6f68456672f5abb35e9dcf7d54226372b66e9d60a7ee26b7a52568e74 | — | |
hash35a672cf34b996b91f3e1c28cbf3a05a37e036e4 | — | |
hashf525d52ceb966516686b482d3dc0137028cc6a63 | — | |
hash54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668 | — | |
hash9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc | — | |
hashfd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb | — | |
hash4140f7e17e6f97f83aa3472473e01add | — | |
hash7bcf8d9f6834c44450eac145a967d2f2 | — | |
hashf92ee93a0af971a3966bfa8efa9c2625 | — | |
hashe65b155ce74f3f81fb7d2b5b60f8e62b36e6d69c | — | |
hashb27b82afa5f15512f3856e549fb83d873fd0049759a4b62ce64c8d7d4dc2c678 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainnpm-cache.com | — | |
domainpypi-get.com | — | |
domainjs-mirror.com | — | |
domainawqhnjewqjkl.icu | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://npm-cache.com:443/router | — | |
urlhttp://awqhnjewqjkl.icu/cdn-cgi/rum | — |
Threat ID: 6a75b64fbf8831d5392a8584
Added to database: 08/07/2026, 10:41:19 UTC
Last enriched: 08/07/2026, 16:45:44 UTC
Last updated: 08/07/2026, 16:45:44 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.