Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Inside a Self-Propagating npm Worm

0
Medium
Published: 08/07/2026 (08/07/2026, 10:27:00 UTC)
Source: AlienVault OTX General

Description

ChainDrop is a self-propagating npm worm that infected over 400 widely used packages, including popular ones like keyv and cacheable-request. It steals sensitive developer credentials such as cloud credentials, npm and GitHub tokens, SSH keys, and extracts temporary credentials from GitHub Actions runner memory. The worm uses stolen npm publishing tokens to infect additional packages while preserving their legitimate functionality. Persistence is maintained through VS Code and Claude Code configurations. ChainDrop employs blockchain-based command-and-control (C2) infrastructure via Ethereum smart contracts, allowing silent reconfiguration of C2 without updating deployed instances. It uses multiple layers of obfuscation and encryption, exfiltrates data through encrypted channels, and publishes stolen tokens in public commit messages.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/07/2026, 16:45:44 UTC

Technical Analysis

ChainDrop is a sophisticated self-propagating malware targeting the npm ecosystem by infecting over 400 packages downloaded hundreds of millions of times weekly. It steals a broad range of developer credentials, including cloud credentials, npm and GitHub tokens, SSH keys, and temporary GitHub Actions runner credentials. The worm leverages stolen npm publishing tokens to propagate by injecting malicious code into additional packages while maintaining their legitimate functionality to avoid detection. Attackers maintain persistence through configurations in VS Code and Claude Code. The malware uses Ethereum smart contracts for blockchain-based command-and-control, enabling the operator to silently update C2 infrastructure via Ethereum transactions without redeploying malware instances. ChainDrop employs three layers of obfuscation and encryption to evade detection, exfiltrates data over encrypted channels, and publicly exposes stolen tokens in commit messages to further its attack chain.

Potential Impact

The infection compromises developer and cloud credentials, including npm and GitHub tokens and SSH keys, potentially allowing attackers to access and manipulate source code repositories, cloud resources, and developer environments. The worm's ability to propagate through npm packages risks widespread supply chain contamination. Persistence mechanisms and blockchain-based C2 infrastructure complicate detection and remediation. The exposure of stolen tokens in public commit messages can lead to further compromise and unauthorized access. This threat undermines the integrity of software supply chains and developer trust.

Defensive Guidance

No official patch or remediation is indicated in the provided data. Since this is a malware campaign exploiting compromised npm packages, remediation involves identifying and removing infected packages from projects and build environments, revoking and rotating exposed credentials (npm tokens, GitHub tokens, SSH keys, cloud credentials), and auditing developer environments for persistence mechanisms such as malicious VS Code and Claude Code configurations. Monitoring for suspicious Ethereum smart contract activity related to C2 may assist in detection. Users should consult vendor advisories and trusted security sources for updated guidance. Patch status is not yet confirmed — check vendor advisories for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/"]
Adversary
null
Pulse Id
6a75b2f415506d0a2374398b
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hashd30b4ea6f68456672f5abb35e9dcf7d54226372b66e9d60a7ee26b7a52568e74
hash35a672cf34b996b91f3e1c28cbf3a05a37e036e4
hashf525d52ceb966516686b482d3dc0137028cc6a63
hash54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668
hash9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc
hashfd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb
hash4140f7e17e6f97f83aa3472473e01add
hash7bcf8d9f6834c44450eac145a967d2f2
hashf92ee93a0af971a3966bfa8efa9c2625
hashe65b155ce74f3f81fb7d2b5b60f8e62b36e6d69c
hashb27b82afa5f15512f3856e549fb83d873fd0049759a4b62ce64c8d7d4dc2c678

Domain

ValueDescriptionCopy
domainnpm-cache.com
domainpypi-get.com
domainjs-mirror.com
domainawqhnjewqjkl.icu

Url

ValueDescriptionCopy
urlhttps://npm-cache.com:443/router
urlhttp://awqhnjewqjkl.icu/cdn-cgi/rum

Threat ID: 6a75b64fbf8831d5392a8584

Added to database: 08/07/2026, 10:41:19 UTC

Last enriched: 08/07/2026, 16:45:44 UTC

Last updated: 08/07/2026, 16:45:44 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses