A New Supply-Chain Threat: ChainDrop Worm Targets npm Packages with Credential Theft

Aug 04, 2026 847 views

A recent worm-like attack, dubbed ChainDrop, has wreaked havoc in the npm ecosystem, affecting 444 packages from over a dozen publishers. This incident underscores a significant threat, given that the compromised packages collectively account for more than 2 billion monthly downloads.

The breach originated from a compromised GitHub account associated with Jared Wray, the maintainer of Keyv, a package that boasts over 150 million weekly downloads for interacting with key-value stores. The attack began when a malicious version, 6.0.0, was uploaded early Tuesday, introducing the Shai-Hulud credential-stealing malware into the mix.

Other packages linked to Wray, including cacheable, flat-cache, and file-entry-cache, were also found to have been trojanized. As the situation escalated, the worm spread to numerous packages from diverse organizations, such as @deliveroo/reevent, @or-sdk/invitations, and many others. As of 18:10 UTC, security researchers from StepSecurity reported detection of the malicious code across 444 packages and 2,212 versions.

StepSecurity's analysis revealed that every infected version employed a standardized infection pattern: a preinstall dropper that installs the legitimate Bun JavaScript runtime, followed by a 710KB obfuscated payload designed to steal credentials, propagate malicious packages, and infiltrate AI development tools.

This variant of malware appears to be an evolution of Shai-Hulud, a troubling credential-stealing worm that’s targeted npm and PyPI repositories for over a year. Researchers have named this new campaign ChainDrop, as it employs Ethereum blockchain technology for command and control through a technique known as EtherHiding.

According to Aikido Security, the infiltration involved directly modifying the main branch with malicious files before swiftly releasing tainted versions to npm, maintaining valid provenance through GitHub Actions.

Wray confirmed on X that he uses OpenID Connect (OIDC) with npm and one-time codes for GitHub access, indicating he didn’t employ long-term static tokens. After regaining control of his GitHub account around 20:00 UTC, he reported that he would conduct a comprehensive audit.

Malware Expands Target Range

The malware introduced two key files, setup.mjs and Math_Symbol.js, renamed to math_init.js in some variations. These files execute during the npm installation process, subsequently downloading and running a secondary obfuscated payload on users' systems.

Once inside, the worm probes the local environment for cloud credentials, developer access tokens, AI configuration files, and cryptocurrency wallets. It’s engineered to identify CI/CD workflows and extract temporary secrets from memory during build processes.

This variant has broadened its scope significantly, encompassing AI-tool credential stores linked to platforms like Claude, OpenAI, and others, as well as integration with cryptocurrency keystores like Solana and Monero. Even system files such as /etc/shadow are not spared, according to independent analysis from security firm Wiz.

Mitigating the Threat

Security teams within enterprises are now faced with the fallout of this incident. A full audit of developer machines is imperative since compromised packages are often transient dependencies for other software. Should developers have installed any of the poisoned versions during the attack window, credentials on affected machines will need to be rotated.

StepSecurity advises a minimum rotation of npm automation tokens, GitHub personal access tokens, and cloud provider credentials, among others. They urged maintainers to treat their publish credentials as potentially exposed, especially given that additional administrator accounts published identical malicious payloads within hours.

The StepSecurity report includes indicators of compromise and a detailed list of affected packages, along with defense recommendations for developer processes that could have mitigated the breach.

Developer teams can enhance security by employing the --ignore-scripts flag in CI workflows, effectively bypassing the preinstall scripts responsible for delivering the malware. Additionally, package managers now offer minimum release age policies, allowing teams to set a grace period of 3 to 7 days before upgrades occur, providing a buffer against potential threats from newly released versions.

Continuous monitoring by security firms remains essential, as malicious versions can often be removed quickly—in this case, within two hours by the npm team. However, the worm’s self-propagating nature poses ongoing risks, especially as it continues to exploit newly compromised developer accounts.

Source: William Martinez · www.csoonline.com

Comments

Sign in to comment.
No comments yet. Be the first to comment.

Related Articles

ChainDrop credential stealing worm infects over 400 npm p...