Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
ID: 2722d877-05a1-5ce5-85e8-4d33e5bc75fc
STIX ID: report--2722d877-05a1-5ce5-85e8-4d33e5bc75fc
Feed Name: Elastic Security Labs
Elastic Security Labs discovered an active Shai-Hulud CHAINDROP supply-chain campaign that trojanized the keyv monorepo and automatically propagates by using stolen npm tokens to backdoor other packages via preinstall hooks; over 400 npm packages were compromised and targeted packages have extremely high monthly downloads. The malware harvests a wide range of credentials (AI tooling, cloud providers, GitHub, npm tokens, SSH keys, Kubernetes tokens), uses an Ethereum smart contract to resolve exfiltration endpoints, and contains a worm component that republishes infected tarballs to npm, with provided IOCs, detection rules, and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
