logo

ChainDrop: Inside a Self-Propagating npm Worm

ID: 239fca9c-90ea-545e-a424-ce902e958ef9

STIX ID: report--239fca9c-90ea-545e-a424-ce902e958ef9

Feed Name: Palo Alto Networks Unit 42

Threat Score
88/100

Date Published: 2026-08-06

Date Updated: 2026-08-07

Author: Unit 42

...
...

A self‑propagating npm worm called ChainDrop (linked to the Shai‑Hulud code lineage) infected hundreds of packages and actively stole developer and cloud credentials, CI secrets (including in‑memory GitHub Actions tokens), SSH keys and other sensitive artifacts, republishing infected packages to spread; it uses an Ethereum smart contract to rotate C2 domains, supports targeted remote code execution, and has been observed across multiple environments with hundreds of public repositories exhibiting exfiltration indicators—Unit 42 provides IoCs, detection guidance, and remediation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.