logo

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

ID: 206e55d8-c3d6-58f7-b195-9735fbb3245c

STIX ID: report--206e55d8-c3d6-58f7-b195-9735fbb3245c

Feed Name: Microsoft Security

Threat Score
90/100

Date Published: 2026-08-04

Date Updated: 2026-08-05

Author: Microsoft Security Research, Ravikant Tiwari, Sagar Patil and Suriyaraj Natarajan

...
...

Microsoft Threat Intelligence describes a large-scale npm supply-chain campaign in which a heavily obfuscated Bun-based JavaScript worm (Mini Shai-Hulud variant) was distributed in malicious package releases across 400+ otherwise unrelated npm packages. The payload executes via npm preinstall hooks on developer workstations and CI/CD runners, harvests npm/GitHub/cloud credentials, exfiltrates encrypted data to attacker-controlled endpoints (with GitHub-based fallback), and propagates by using stolen npm tokens and GitHub credentials to republish compromised packages and inject persistence into repositories and developer tooling; Microsoft provides detection, mitigation, IOC lists, and hunting queries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.