Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack
ChainDrop is a self-propagating worm that has compromised over 400 npm packages in a major software supply chain attack. It exploits stolen npm publishing credentials to modify and republish legitimate software releases automatically. The malware targets developer workstations and CI/CD environments, stealing credentials from multiple platforms including npm, GitHub, AWS, Kubernetes, and HashiCorp Vault. It uses preinstall lifecycle scripts for automatic execution and persists by modifying repository configurations and abusing GitHub Actions OIDC workflows. After stealing credentials, ChainDrop autonomously propagates by inserting malicious payloads into packages and republishing them with incremented versions, enabling widespread compromise of the software ecosystem.
AI Analysis
Technical Summary
ChainDrop is a large-scale software supply chain malware campaign that compromises npm packages by leveraging stolen publishing credentials. It operates as a self-propagating worm, infecting developer workstations and CI/CD pipelines to harvest credentials from various cloud and development platforms. The malware uses lifecycle scripts to execute automatically during package installation and establishes persistence through repository configuration changes and abuse of GitHub Actions OIDC trusted workflows. It then autonomously downloads npm packages, injects malicious code, increments version numbers, and republishes them, thereby spreading the infection across the npm ecosystem. This attack demonstrates how compromised developer identities and CI/CD environments can facilitate extensive supply chain compromises.
Potential Impact
The attack compromises the integrity of over 400 npm packages by injecting malicious payloads, potentially affecting any software relying on these packages. It enables attackers to steal credentials from multiple critical platforms (npm, GitHub, AWS, Kubernetes, HashiCorp Vault), which can lead to further unauthorized access and resource enumeration. The self-propagating nature of the worm allows rapid and widespread infection across the software supply chain, increasing the risk to developers and downstream users of affected packages.
Mitigation Recommendations
No official patch or remediation is indicated in the provided data. Since this attack exploits stolen credentials and abuses CI/CD workflows, mitigation should focus on securing developer credentials, enforcing multi-factor authentication, auditing and restricting CI/CD pipeline permissions, and monitoring for unauthorized package modifications. Developers should verify the integrity of npm packages before use and consider implementing supply chain security best practices such as signing packages and using trusted sources. Check vendor advisories and npm security updates for any official guidance or fixes.
Indicators of Compromise
- hash: 54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668
- hash: f92ee93a0af971a3966bfa8efa9c2625
- hash: e65b155ce74f3f81fb7d2b5b60f8e62b36e6d69c
Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack
Description
ChainDrop is a self-propagating worm that has compromised over 400 npm packages in a major software supply chain attack. It exploits stolen npm publishing credentials to modify and republish legitimate software releases automatically. The malware targets developer workstations and CI/CD environments, stealing credentials from multiple platforms including npm, GitHub, AWS, Kubernetes, and HashiCorp Vault. It uses preinstall lifecycle scripts for automatic execution and persists by modifying repository configurations and abusing GitHub Actions OIDC workflows. After stealing credentials, ChainDrop autonomously propagates by inserting malicious payloads into packages and republishing them with incremented versions, enabling widespread compromise of the software ecosystem.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
ChainDrop is a large-scale software supply chain malware campaign that compromises npm packages by leveraging stolen publishing credentials. It operates as a self-propagating worm, infecting developer workstations and CI/CD pipelines to harvest credentials from various cloud and development platforms. The malware uses lifecycle scripts to execute automatically during package installation and establishes persistence through repository configuration changes and abuse of GitHub Actions OIDC trusted workflows. It then autonomously downloads npm packages, injects malicious code, increments version numbers, and republishes them, thereby spreading the infection across the npm ecosystem. This attack demonstrates how compromised developer identities and CI/CD environments can facilitate extensive supply chain compromises.
Potential Impact
The attack compromises the integrity of over 400 npm packages by injecting malicious payloads, potentially affecting any software relying on these packages. It enables attackers to steal credentials from multiple critical platforms (npm, GitHub, AWS, Kubernetes, HashiCorp Vault), which can lead to further unauthorized access and resource enumeration. The self-propagating nature of the worm allows rapid and widespread infection across the software supply chain, increasing the risk to developers and downstream users of affected packages.
Defensive Guidance
No official patch or remediation is indicated in the provided data. Since this attack exploits stolen credentials and abuses CI/CD workflows, mitigation should focus on securing developer credentials, enforcing multi-factor authentication, auditing and restricting CI/CD pipeline permissions, and monitoring for unauthorized package modifications. Developers should verify the integrity of npm packages before use and consider implementing supply chain security best practices such as signing packages and using trusted sources. Check vendor advisories and npm security updates for any official guidance or fixes.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://blog.polyswarm.io/self-propagating-chaindrop-worm-infects-more-than-400-npm-packages-in-major-software-supply-chain-attack"]
- Adversary
- null
- Pulse Id
- 6a7b39b0e4765559a182c347
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668 | — | |
hashf92ee93a0af971a3966bfa8efa9c2625 | — | |
hashe65b155ce74f3f81fb7d2b5b60f8e62b36e6d69c | — |
Threat ID: 6a7b3f17bf8831d539f29cec
Added to database: 08/11/2026, 15:26:15 UTC
Last enriched: 08/11/2026, 15:48:58 UTC
Last updated: 08/12/2026, 01:50:47 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.