Tracking Shai-Hulud: Inside the ChainDrop NPM Worm
On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.
AI Analysis
Technical Summary
On August 4, 2026, the ChainDrop worm, a variant of Mini Shai-Hulud associated with TeamPCP, compromised the npm ecosystem by abusing a maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories and leveraged legitimate CI/CD pipelines to publish poisoned npm packages carrying valid SLSA Build Level 3 provenance attestations, making the malicious packages indistinguishable from legitimate releases. ChainDrop rapidly propagated to over 400 npm packages within four hours by stealing npm tokens and republishing infected versions. The worm's command and control infrastructure is implemented via Ethereum smart contracts, allowing domain rotation without altering the deployed malware. It includes destructive functionality that wipes victim home directories if tokens are revoked and maintains persistence through IDE and AI-agent configuration files. The malware harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data through GitHub repositories and EtherHiding techniques.
Potential Impact
ChainDrop compromises the npm supply chain by injecting malicious code into widely used packages, enabling rapid propagation across hundreds of packages. It steals authentication tokens to republish infected packages, undermining trust in the software supply chain. The worm's destructive payload can wipe victim home directories, causing data loss. It also harvests sensitive credentials from multiple cloud and development platforms, risking extensive data exfiltration and further compromise of cloud and infrastructure environments. The use of Ethereum smart contracts for C2 infrastructure complicates detection and takedown efforts due to domain rotation capabilities. Persistence through IDE and AI-agent configuration files increases the difficulty of complete removal.
Mitigation Recommendations
No official patch or fix is indicated in the available data. Organizations should immediately audit and revoke compromised npm tokens and credentials associated with affected maintainer accounts. Review and harden CI/CD pipeline security to prevent unauthorized package publishing. Monitor for indicators of compromise such as the listed malicious domains and hashes. Investigate and clean infected development environments, including IDE and AI-agent configuration files, to remove persistence mechanisms. Employ credential rotation and enhanced monitoring on cloud and development platforms to detect and respond to potential exfiltration attempts. Consult the referenced vendor advisory and threat intelligence sources for ongoing updates and guidance.
Indicators of Compromise
- domain: npm-cache.com
- hash: 35a672cf34b996b91f3e1c28cbf3a05a37e036e4
- hash: f525d52ceb966516686b482d3dc0137028cc6a63
- hash: 54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668
- hash: 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc
- hash: fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb
- url: https://npm-cache.com:443/router
- hash: 4140f7e17e6f97f83aa3472473e01add
- hash: 7bcf8d9f6834c44450eac145a967d2f2
- hash: f92ee93a0af971a3966bfa8efa9c2625
- hash: e65b155ce74f3f81fb7d2b5b60f8e62b36e6d69c
- domain: awqhnjewqjkl.icu
- domain: copilot-instructions.md
Tracking Shai-Hulud: Inside the ChainDrop NPM Worm
Description
On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
On August 4, 2026, the ChainDrop worm, a variant of Mini Shai-Hulud associated with TeamPCP, compromised the npm ecosystem by abusing a maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories and leveraged legitimate CI/CD pipelines to publish poisoned npm packages carrying valid SLSA Build Level 3 provenance attestations, making the malicious packages indistinguishable from legitimate releases. ChainDrop rapidly propagated to over 400 npm packages within four hours by stealing npm tokens and republishing infected versions. The worm's command and control infrastructure is implemented via Ethereum smart contracts, allowing domain rotation without altering the deployed malware. It includes destructive functionality that wipes victim home directories if tokens are revoked and maintains persistence through IDE and AI-agent configuration files. The malware harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data through GitHub repositories and EtherHiding techniques.
Potential Impact
ChainDrop compromises the npm supply chain by injecting malicious code into widely used packages, enabling rapid propagation across hundreds of packages. It steals authentication tokens to republish infected packages, undermining trust in the software supply chain. The worm's destructive payload can wipe victim home directories, causing data loss. It also harvests sensitive credentials from multiple cloud and development platforms, risking extensive data exfiltration and further compromise of cloud and infrastructure environments. The use of Ethereum smart contracts for C2 infrastructure complicates detection and takedown efforts due to domain rotation capabilities. Persistence through IDE and AI-agent configuration files increases the difficulty of complete removal.
Defensive Guidance
No official patch or fix is indicated in the available data. Organizations should immediately audit and revoke compromised npm tokens and credentials associated with affected maintainer accounts. Review and harden CI/CD pipeline security to prevent unauthorized package publishing. Monitor for indicators of compromise such as the listed malicious domains and hashes. Investigate and clean infected development environments, including IDE and AI-agent configuration files, to remove persistence mechanisms. Employ credential rotation and enhanced monitoring on cloud and development platforms to detect and respond to potential exfiltration attempts. Consult the referenced vendor advisory and threat intelligence sources for ongoing updates and guidance.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.zscaler.com/blogs/security-research/tracking-shai-hulud-inside-chaindrop-npm-worm"]
- Adversary
- TeamPCP
- Pulse Id
- 6a7bdb4167c384aad06f1253
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainnpm-cache.com | — | |
domainawqhnjewqjkl.icu | — | |
domaincopilot-instructions.md | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash35a672cf34b996b91f3e1c28cbf3a05a37e036e4 | — | |
hashf525d52ceb966516686b482d3dc0137028cc6a63 | — | |
hash54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668 | — | |
hash9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc | — | |
hashfd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb | — | |
hash4140f7e17e6f97f83aa3472473e01add | — | |
hash7bcf8d9f6834c44450eac145a967d2f2 | — | |
hashf92ee93a0af971a3966bfa8efa9c2625 | — | |
hashe65b155ce74f3f81fb7d2b5b60f8e62b36e6d69c | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://npm-cache.com:443/router | — |
Threat ID: 6a7c158ebf8831d5391cfb29
Added to database: 08/12/2026, 06:41:18 UTC
Last enriched: 08/12/2026, 09:34:02 UTC
Last updated: 08/12/2026, 18:17:19 UTC
Views: 25
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.