logo

ChainDrop worm crawls into npm supply chain, evades standard defenses

ID: bbadee9e-f7d5-5f99-9016-a1ee6667f7e7

STIX ID: report--bbadee9e-f7d5-5f99-9016-a1ee6667f7e7

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2026-08-15

Date Updated: 2026-08-15

...
...

A new Shai-Hulud variant named ChainDrop has been observed in a large npm supply-chain campaign that poisoned 444 packages (collectively downloaded ~2 billion times/month). It stealthily propagates by modifying tarballs and inserting startup hooks into repository configuration (e.g., .claude/settings.json, .vscode/tasks.json), harvests npm tokens, cloud keys and secrets, exfiltrates data to attacker-controlled endpoints, and can commit malicious config to accessible GitHub branches to spread further; affected packages were removed from npm and vendors published lists of compromised packages and versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.