Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack

0
Medium
Published: 08/11/2026 (08/11/2026, 15:03:12 UTC)
Source: AlienVault OTX General

Description

ChainDrop is a self-propagating worm that has compromised over 400 npm packages in a major software supply chain attack. It exploits stolen npm publishing credentials to modify and republish legitimate software releases automatically. The malware targets developer workstations and CI/CD environments, stealing credentials from multiple platforms including npm, GitHub, AWS, Kubernetes, and HashiCorp Vault. It uses preinstall lifecycle scripts for automatic execution and persists by modifying repository configurations and abusing GitHub Actions OIDC workflows. After stealing credentials, ChainDrop autonomously propagates by inserting malicious payloads into packages and republishing them with incremented versions, enabling widespread compromise of the software ecosystem.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/11/2026, 15:48:58 UTC

Technical Analysis

ChainDrop is a large-scale software supply chain malware campaign that compromises npm packages by leveraging stolen publishing credentials. It operates as a self-propagating worm, infecting developer workstations and CI/CD pipelines to harvest credentials from various cloud and development platforms. The malware uses lifecycle scripts to execute automatically during package installation and establishes persistence through repository configuration changes and abuse of GitHub Actions OIDC trusted workflows. It then autonomously downloads npm packages, injects malicious code, increments version numbers, and republishes them, thereby spreading the infection across the npm ecosystem. This attack demonstrates how compromised developer identities and CI/CD environments can facilitate extensive supply chain compromises.

Potential Impact

The attack compromises the integrity of over 400 npm packages by injecting malicious payloads, potentially affecting any software relying on these packages. It enables attackers to steal credentials from multiple critical platforms (npm, GitHub, AWS, Kubernetes, HashiCorp Vault), which can lead to further unauthorized access and resource enumeration. The self-propagating nature of the worm allows rapid and widespread infection across the software supply chain, increasing the risk to developers and downstream users of affected packages.

Defensive Guidance

No official patch or remediation is indicated in the provided data. Since this attack exploits stolen credentials and abuses CI/CD workflows, mitigation should focus on securing developer credentials, enforcing multi-factor authentication, auditing and restricting CI/CD pipeline permissions, and monitoring for unauthorized package modifications. Developers should verify the integrity of npm packages before use and consider implementing supply chain security best practices such as signing packages and using trusted sources. Check vendor advisories and npm security updates for any official guidance or fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://blog.polyswarm.io/self-propagating-chaindrop-worm-infects-more-than-400-npm-packages-in-major-software-supply-chain-attack"]
Adversary
null
Pulse Id
6a7b39b0e4765559a182c347
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668
hashf92ee93a0af971a3966bfa8efa9c2625
hashe65b155ce74f3f81fb7d2b5b60f8e62b36e6d69c

Threat ID: 6a7b3f17bf8831d539f29cec

Added to database: 08/11/2026, 15:26:15 UTC

Last enriched: 08/11/2026, 15:48:58 UTC

Last updated: 08/12/2026, 01:50:47 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses