Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
On August 4, 2026, a sophisticated supply chain attack compromised the keyv npm package maintainer, deploying CHAINDROP, a self-propagating worm that automatically backdoors packages using stolen npm credentials. Over 400 npm packages were infected, affecting more than 1.3 billion monthly downloads. The worm executes via preinstall hooks, deploys across Linux, macOS, and Windows platforms, and harvests credentials from over 300 patterns targeting AI tooling, cloud providers, GitHub tokens, and npm credentials. CHAINDROP uses Ethereum smart contracts for C2 resolution and propagates by publishing trojanized versions of packages the compromised maintainer can access. The payload is heavily obfuscated and contains Dune-themed references consistent with previous Shai-Hulud campaigns.
AI Analysis
Technical Summary
CHAINDROP is a self-propagating worm deployed in a supply chain attack that compromised the keyv npm package maintainer. It infects npm packages by leveraging stolen npm credentials to publish trojanized versions. The worm executes via preinstall hooks across multiple operating systems and harvests credentials from over 300 patterns targeting AI tooling, cloud providers, GitHub tokens, and npm credentials. Its command and control infrastructure uses Ethereum smart contracts for resolution. The malware payload is heavily obfuscated and contains thematic references consistent with the Shai-Hulud adversary group. Over 400 npm packages were infected, affecting a large user base with over 1.3 billion monthly downloads. Indicators include malicious domains and multiple file hashes. No CVE or patch information is available.
Potential Impact
The attack compromises the integrity of widely used npm packages, potentially allowing attackers to execute arbitrary code on systems where infected packages are installed. Credential harvesting capabilities enable further compromise of developer and cloud environments. The widespread infection affects a significant portion of the npm ecosystem, risking supply chain trust and exposing users to backdoors and data theft. The multi-platform execution increases the scope of affected environments.
Mitigation Recommendations
No official patch or remediation guidance is provided in the available data. Since this is a supply chain compromise involving npm packages, mitigation should focus on auditing and verifying package integrity, rotating any potentially exposed credentials (npm, GitHub, cloud providers), and monitoring for use of the identified malicious indicators such as domains and file hashes. Users should avoid installing or updating packages from compromised maintainers until the issue is resolved. Check the referenced vendor advisory and npm security announcements for updates and official remediation steps.
Indicators of Compromise
- domain: npm-cache.com
- hash: 35a672cf34b996b91f3e1c28cbf3a05a37e036e4
- hash: f525d52ceb966516686b482d3dc0137028cc6a63
- hash: 54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668
- hash: 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc
- hash: fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb
- hash: 4140f7e17e6f97f83aa3472473e01add
- hash: 7bcf8d9f6834c44450eac145a967d2f2
- hash: f92ee93a0af971a3966bfa8efa9c2625
- hash: e65b155ce74f3f81fb7d2b5b60f8e62b36e6d69c
- domain: awqhnjewqjkl.icu
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
Description
On August 4, 2026, a sophisticated supply chain attack compromised the keyv npm package maintainer, deploying CHAINDROP, a self-propagating worm that automatically backdoors packages using stolen npm credentials. Over 400 npm packages were infected, affecting more than 1.3 billion monthly downloads. The worm executes via preinstall hooks, deploys across Linux, macOS, and Windows platforms, and harvests credentials from over 300 patterns targeting AI tooling, cloud providers, GitHub tokens, and npm credentials. CHAINDROP uses Ethereum smart contracts for C2 resolution and propagates by publishing trojanized versions of packages the compromised maintainer can access. The payload is heavily obfuscated and contains Dune-themed references consistent with previous Shai-Hulud campaigns.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CHAINDROP is a self-propagating worm deployed in a supply chain attack that compromised the keyv npm package maintainer. It infects npm packages by leveraging stolen npm credentials to publish trojanized versions. The worm executes via preinstall hooks across multiple operating systems and harvests credentials from over 300 patterns targeting AI tooling, cloud providers, GitHub tokens, and npm credentials. Its command and control infrastructure uses Ethereum smart contracts for resolution. The malware payload is heavily obfuscated and contains thematic references consistent with the Shai-Hulud adversary group. Over 400 npm packages were infected, affecting a large user base with over 1.3 billion monthly downloads. Indicators include malicious domains and multiple file hashes. No CVE or patch information is available.
Potential Impact
The attack compromises the integrity of widely used npm packages, potentially allowing attackers to execute arbitrary code on systems where infected packages are installed. Credential harvesting capabilities enable further compromise of developer and cloud environments. The widespread infection affects a significant portion of the npm ecosystem, risking supply chain trust and exposing users to backdoors and data theft. The multi-platform execution increases the scope of affected environments.
Defensive Guidance
No official patch or remediation guidance is provided in the available data. Since this is a supply chain compromise involving npm packages, mitigation should focus on auditing and verifying package integrity, rotating any potentially exposed credentials (npm, GitHub, cloud providers), and monitoring for use of the identified malicious indicators such as domains and file hashes. Users should avoid installing or updating packages from compromised maintainers until the issue is resolved. Check the referenced vendor advisory and npm security announcements for updates and official remediation steps.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain"]
- Adversary
- Shai-Hulud
- Pulse Id
- 6a73cac4902afff959b758aa
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainnpm-cache.com | — | |
domainawqhnjewqjkl.icu | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash35a672cf34b996b91f3e1c28cbf3a05a37e036e4 | — | |
hashf525d52ceb966516686b482d3dc0137028cc6a63 | — | |
hash54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668 | — | |
hash9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc | — | |
hashfd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb | — | |
hash4140f7e17e6f97f83aa3472473e01add | — | |
hash7bcf8d9f6834c44450eac145a967d2f2 | — | |
hashf92ee93a0af971a3966bfa8efa9c2625 | — | |
hashe65b155ce74f3f81fb7d2b5b60f8e62b36e6d69c | — |
Threat ID: 6a744c2ebf8831d539758e9c
Added to database: 08/06/2026, 08:56:14 UTC
Last enriched: 08/06/2026, 10:34:00 UTC
Last updated: 08/06/2026, 20:24:50 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.