Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack
A large-scale software supply chain attack compromised over 400 npm packages through a self-propagating worm called ChainDrop, a new variant of Mini Shai-Hulud. The campaign exploits stolen npm publishing credentials to automatically modify and republish legitimate software releases. ChainDrop targets developer workstations and CI/CD environments, harvesting credentials from npm, GitHub, AWS, Kubernetes, and HashiCorp Vault before validating access and enumerating resources. The malware uses preinstall lifecycle scripts for automatic execution, establishes persistence through repository configuration modifications, and abuses GitHub Actions OIDC trusted publishing workflows. After stealing credentials, it autonomously propagates by downloading packages, inserting malicious payloads, and republishing them with incremented versions, demonstrating how compromised developer identities can enable widespread ecosystem compromise.
AI Analysis
Technical Summary
ChainDrop is a large-scale software supply chain malware campaign that compromises npm packages by leveraging stolen publishing credentials. It operates as a self-propagating worm, infecting developer workstations and CI/CD pipelines to harvest credentials from various cloud and development platforms. The malware uses lifecycle scripts to execute automatically during package installation and establishes persistence through repository configuration changes and abuse of GitHub Actions OIDC trusted workflows. It then autonomously downloads npm packages, injects malicious code, increments version numbers, and republishes them, thereby spreading the infection across the npm ecosystem. This attack demonstrates how compromised developer identities and CI/CD environments can facilitate extensive supply chain compromises.
Potential Impact
The attack compromises the integrity of over 400 npm packages by injecting malicious payloads, potentially affecting any software relying on these packages. It enables attackers to steal credentials from multiple critical platforms (npm, GitHub, AWS, Kubernetes, HashiCorp Vault), which can lead to further unauthorized access and resource enumeration. The self-propagating nature of the worm allows rapid and widespread infection across the software supply chain, increasing the risk to developers and downstream users of affected packages.
Mitigation Recommendations
No official patch or remediation is indicated in the provided data. Since this attack exploits stolen credentials and abuses CI/CD workflows, mitigation should focus on securing developer credentials, enforcing multi-factor authentication, auditing and restricting CI/CD pipeline permissions, and monitoring for unauthorized package modifications. Developers should verify the integrity of npm packages before use and consider implementing supply chain security best practices such as signing packages and using trusted sources. Check vendor advisories and npm security updates for any official guidance or fixes.
Indicators of Compromise
- hash: 54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668
- hash: f92ee93a0af971a3966bfa8efa9c2625
- hash: e65b155ce74f3f81fb7d2b5b60f8e62b36e6d69c
Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack
Description
A large-scale software supply chain attack compromised over 400 npm packages through a self-propagating worm called ChainDrop, a new variant of Mini Shai-Hulud. The campaign exploits stolen npm publishing credentials to automatically modify and republish legitimate software releases. ChainDrop targets developer workstations and CI/CD environments, harvesting credentials from npm, GitHub, AWS, Kubernetes, and HashiCorp Vault before validating access and enumerating resources. The malware uses preinstall lifecycle scripts for automatic execution, establishes persistence through repository configuration modifications, and abuses GitHub Actions OIDC trusted publishing workflows. After stealing credentials, it autonomously propagates by downloading packages, inserting malicious payloads, and republishing them with incremented versions, demonstrating how compromised developer identities can enable widespread ecosystem compromise.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
ChainDrop is a large-scale software supply chain malware campaign that compromises npm packages by leveraging stolen publishing credentials. It operates as a self-propagating worm, infecting developer workstations and CI/CD pipelines to harvest credentials from various cloud and development platforms. The malware uses lifecycle scripts to execute automatically during package installation and establishes persistence through repository configuration changes and abuse of GitHub Actions OIDC trusted workflows. It then autonomously downloads npm packages, injects malicious code, increments version numbers, and republishes them, thereby spreading the infection across the npm ecosystem. This attack demonstrates how compromised developer identities and CI/CD environments can facilitate extensive supply chain compromises.
Potential Impact
The attack compromises the integrity of over 400 npm packages by injecting malicious payloads, potentially affecting any software relying on these packages. It enables attackers to steal credentials from multiple critical platforms (npm, GitHub, AWS, Kubernetes, HashiCorp Vault), which can lead to further unauthorized access and resource enumeration. The self-propagating nature of the worm allows rapid and widespread infection across the software supply chain, increasing the risk to developers and downstream users of affected packages.
Defensive Guidance
No official patch or remediation is indicated in the provided data. Since this attack exploits stolen credentials and abuses CI/CD workflows, mitigation should focus on securing developer credentials, enforcing multi-factor authentication, auditing and restricting CI/CD pipeline permissions, and monitoring for unauthorized package modifications. Developers should verify the integrity of npm packages before use and consider implementing supply chain security best practices such as signing packages and using trusted sources. Check vendor advisories and npm security updates for any official guidance or fixes.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://blog.polyswarm.io/self-propagating-chaindrop-worm-infects-more-than-400-npm-packages-in-major-software-supply-chain-attack"]
- Pulse Id
- 6a7b39b0e4765559a182c347
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668 | — | |
hashf92ee93a0af971a3966bfa8efa9c2625 | — | |
hashe65b155ce74f3f81fb7d2b5b60f8e62b36e6d69c | — |
Threat ID: 6a7b3f17bf8831d539f29cec
Added to database: 08/11/2026, 15:26:15 UTC
Last enriched: 08/11/2026, 15:48:58 UTC
Last updated: 09/26/2026, 09:54:15 UTC
Views: 112
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.