ChainDrop is a cross-platform, self-propagating npm supply-chain worm derived from the Shai-Hulud lineage and identified in August 2026. Its campaign began with compromise of a maintainer account associated with the keyv ecosystem and spread to more than 400 npm packages. It targets developer workstations and CI/CD environments on Linux, macOS, and Windows, exploiting the credentials available to those systems to compromise additional packages and repositories.
Infected packages retain their legitimate functionality but include a malicious preinstall lifecycle hook that launches a dropper and an obfuscated JavaScript payload. The dropper downloads the legitimate Bun runtime when necessary and uses it to execute the malware. ChainDrop harvests npm and GitHub tokens, cloud credentials, SSH keys, Kubernetes and HashiCorp Vault tokens, infrastructure configuration data, and AI coding-tool secrets. It searches local files, environment variables, cloud metadata services, and build-process memory, including GitHub Actions runner memory containing temporary OIDC tokens and runner secrets. It also validates credentials and enumerates accessible repositories, cloud resources, and permissions.
Using stolen npm credentials with sufficient publishing permissions, ChainDrop retrieves writable packages, injects its malicious components, increments their patch versions, and republishes them. Captured GitHub credentials also enable repository modification and persistence through VS Code project-opening tasks and Claude Code session-start hooks, allowing execution independently of subsequent package installations. Compromised trusted publishing workflows can produce malicious releases with valid provenance attestations.
ChainDrop compresses and encrypts stolen data before exfiltration. It resolves exfiltration infrastructure through an Ethereum smart contract, allowing operators to rotate destinations without updating infected packages. GitHub commit history provides a fallback discovery mechanism, and public repositories created under compromised accounts provide an additional exfiltration channel.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On August 4, 2026, a self-propagating worm called ChainDrop entered the npm ecosystem through a compromised maintainer account. ChainDrop is a variant of Mini Shai-Hulud linked to TeamPCP.
The attackers trojanized the monorepo and embedded a self-propagating worm called CHAINDROP that uses stolen npm credentials to automatically backdoor every other package the maintainer had publish rights to.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
The worm component activates when the credential sweep turns up an npm token... Once a qualifying token is found, the worm enumerates every package the victim has publish rights to.
If it finds any, it queries the GitHub API to list all accessible repositories and branches
Rather than just hunting for bugs in finished software, attackers are targeting the everyday tools and code developers rely on. Unit 42 research shows this happening at every step of the building process.
Execution: Used a preinstall hook to download the Bun runtime and execute the obfuscated Math_Symbol.js payload. | Downloads the Bun JavaScript runtime v1.3.13 directly from its official GitHub release page. Launches the second-stage payload via Bun.
a hidden Python script directly read live process memory from GitHub Actions runners
Execution is triggered via a preinstall hook in package.json. This abuses a legitimate npm feature that will run arbitrary commands before a package is installed.
Even if you never install an infected package (“ npm install ” in npm argot), you can still get the nasties – though that is one possible route of infection.
The worm component activates when the credential sweep turns up an npm token... Once a qualifying token is found, the worm enumerates every package the victim has publish rights to.
a hidden Python script directly read live process memory from GitHub Actions runners to steal temporary OpenID Connect (OIDC) tokens and secrets
The worm component activates when the credential sweep turns up an npm token... Once a qualifying token is found, the worm enumerates every package the victim has publish rights to.
The payload is heavily obfuscated at 711 kilobytes, employing control-flow flattening with a string encoding scheme using Base91.
a hidden Python script directly read live process memory from GitHub Actions runners to steal temporary OpenID Connect (OIDC) tokens and secrets
After execution, the bun temporary directory is deleted to cover its tracks.
The worm component activates when the credential sweep turns up an npm token... Once a qualifying token is found, the worm enumerates every package the victim has publish rights to.
If it finds any, it queries the GitHub API to list all accessible repositories and branches
It looks in shell configurations, environment variables and even live memory.
When executed, the software scours the user’s workspace for npm tokens with full write privileges
Its collector scanned for more than 300 credential patterns, including OpenAI, Anthropic and Cursor keys.
It looks in shell configurations, environment variables and even live memory.
It looks in shell configurations, environment variables and even live memory.
The payload has a component called collector that functions as a credential harvester... Many other credentials are targeted, such as GitHub ... SSH private keys, Kubernetes service account tokens, and npm tokens.
The malware also targets cloud provider credentials from AWS, GCP, Azure, and Alibaba Cloud.
ChainDrop fans out across three RPC providers ( eth.llamarpc.com , go.getblock.io , eth-mainnet.nodereal.io ), so a rate-limited or downed endpoint does not break resolution.
Even its command infrastructure was parked inside an Ethereum smart contract, rendering any domain blocklists moot.
If these two previous paths fail, CHAINDROP will exfiltrate the data via a public GitHub repository ... using the compromised victim's account.
The dropper will detect the platform/architecture of the machine and download bun v1.3.13 directly from the official release page. It will extract bun, then use it to execute the payload.
The ABI-decoded response holds the C2 pointer. Operators pick the encoding: a plain UTF-8 URL, Base64, Base64 plus XOR, gzip plus Base64, or a bash one-liner.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Self-propagating npm supply-chain malware that steals cloud credentials, npm and GitHub tokens, SSH keys, Kubernetes and Vault tokens, Terraform state files, and developer secrets. It also searches GitHub Actions runner memory for temporary OIDC tokens and runner secrets. An Ethereum smart contract resolves its exfiltration destination, allowing operators to rotate infrastructure without updating infected packages. It executes through package preinstall scripts and establishes persistence through VS Code tasks and Claude Code SessionStart hooks.
Self-propagating npm worm that uses a preinstall hook and a custom Bun runtime to execute an obfuscated credential harvester. It searches disk files and running build-process memory for cloud IAM credentials, CI/CD tokens and short-lived OIDC federation keys. It uses blockchain-based EtherHiding for dynamic endpoint resolution and installs persistent task hooks triggered by project opening or AI coding sessions.
Referenced only as background for previous npm supply-chain incidents.
A supply-chain worm variant that compromised package releases through legitimate signed maintainer pipelines, resulting in poisoned packages with valid SLSA provenance attestations. Its command infrastructure was hosted through an Ethereum smart contract to resist conventional domain-based blocking.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.