ChainDrop: The Mini Shai Hulud npm worm’s latest wave hits keyv and cacheable
ID: 8d36db19-c98a-52dc-aa9d-7dbc18346cbe
STIX ID: report--8d36db19-c98a-52dc-aa9d-7dbc18346cbe
Feed Name: Expel Blog
ChainDrop is a self‑propagating npm supply‑chain worm (disclosed 2026-08-04) that compromised a maintainer’s GitHub for widely used Node.js utilities (keyv, cacheable, flat-cache, file-entry-cache), added a hidden preinstall script (setup.mjs) which pulls a Bun runtime and executes an obfuscated credential‑stealing payload (Math_Symbol.js) to harvest npm/GitHub/AWS/Kubernetes/Vault secrets and exfiltrate them; stolen npm tokens are then used to publish backdoored packages to downstream projects — organizations should audit lockfiles, rotate credentials, and review CI/CD and registry activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
