Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Tracking Shai-Hulud: Inside the ChainDrop NPM Worm

0
Medium
Published: 08/12/2026 (08/12/2026, 02:32:33 UTC)
Source: AlienVault OTX General

Description

On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 09:34:02 UTC

Technical Analysis

On August 4, 2026, the ChainDrop worm, a variant of Mini Shai-Hulud associated with TeamPCP, compromised the npm ecosystem by abusing a maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories and leveraged legitimate CI/CD pipelines to publish poisoned npm packages carrying valid SLSA Build Level 3 provenance attestations, making the malicious packages indistinguishable from legitimate releases. ChainDrop rapidly propagated to over 400 npm packages within four hours by stealing npm tokens and republishing infected versions. The worm's command and control infrastructure is implemented via Ethereum smart contracts, allowing domain rotation without altering the deployed malware. It includes destructive functionality that wipes victim home directories if tokens are revoked and maintains persistence through IDE and AI-agent configuration files. The malware harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data through GitHub repositories and EtherHiding techniques.

Potential Impact

ChainDrop compromises the npm supply chain by injecting malicious code into widely used packages, enabling rapid propagation across hundreds of packages. It steals authentication tokens to republish infected packages, undermining trust in the software supply chain. The worm's destructive payload can wipe victim home directories, causing data loss. It also harvests sensitive credentials from multiple cloud and development platforms, risking extensive data exfiltration and further compromise of cloud and infrastructure environments. The use of Ethereum smart contracts for C2 infrastructure complicates detection and takedown efforts due to domain rotation capabilities. Persistence through IDE and AI-agent configuration files increases the difficulty of complete removal.

Defensive Guidance

No official patch or fix is indicated in the available data. Organizations should immediately audit and revoke compromised npm tokens and credentials associated with affected maintainer accounts. Review and harden CI/CD pipeline security to prevent unauthorized package publishing. Monitor for indicators of compromise such as the listed malicious domains and hashes. Investigate and clean infected development environments, including IDE and AI-agent configuration files, to remove persistence mechanisms. Employ credential rotation and enhanced monitoring on cloud and development platforms to detect and respond to potential exfiltration attempts. Consult the referenced vendor advisory and threat intelligence sources for ongoing updates and guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.zscaler.com/blogs/security-research/tracking-shai-hulud-inside-chaindrop-npm-worm"]
Adversary
TeamPCP
Pulse Id
6a7bdb4167c384aad06f1253
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainnpm-cache.com
domainawqhnjewqjkl.icu
domaincopilot-instructions.md

Hash

ValueDescriptionCopy
hash35a672cf34b996b91f3e1c28cbf3a05a37e036e4
hashf525d52ceb966516686b482d3dc0137028cc6a63
hash54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668
hash9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc
hashfd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb
hash4140f7e17e6f97f83aa3472473e01add
hash7bcf8d9f6834c44450eac145a967d2f2
hashf92ee93a0af971a3966bfa8efa9c2625
hashe65b155ce74f3f81fb7d2b5b60f8e62b36e6d69c

Url

ValueDescriptionCopy
urlhttps://npm-cache.com:443/router

Threat ID: 6a7c158ebf8831d5391cfb29

Added to database: 08/12/2026, 06:41:18 UTC

Last enriched: 08/12/2026, 09:34:02 UTC

Last updated: 08/12/2026, 18:17:19 UTC

Views: 25

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses