logo

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

ID: 2722d877-05a1-5ce5-85e8-4d33e5bc75fc

STIX ID: report--2722d877-05a1-5ce5-85e8-4d33e5bc75fc

Feed Name: Elastic Security Labs

Threat Score
92/100

Date Published: 2026-08-06

Date Updated: 2026-08-05

...
...

Elastic Security Labs discovered an active Shai-Hulud CHAINDROP supply-chain campaign that trojanized the keyv monorepo and automatically propagates by using stolen npm tokens to backdoor other packages via preinstall hooks; over 400 npm packages were compromised and targeted packages have extremely high monthly downloads. The malware harvests a wide range of credentials (AI tooling, cloud providers, GitHub, npm tokens, SSH keys, Kubernetes tokens), uses an Ethereum smart contract to resolve exfiltration endpoints, and contains a worm component that republishes infected tarballs to npm, with provided IOCs, detection rules, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.