bleeping-computer · Crawled Aug 4, 2026

Massive ChainDrop npm supply-chain attack infects hundreds of packages

5 IoCs 1 Malware
Read original article ↗

AI Summary

A massive supply-chain attack dubbed ChainDrop has compromised over 1,300 npm packages with a combined 2 billion monthly downloads. The attack began with the compromise of the Keyv maintainer's GitHub account, allowing the threat actor to push malicious code directly to main branches and publish poisoned versions through legitimate CI/CD workflows. The malware, named ChainDrop and based on the Shai-Hulud worm, includes a dropper (setup.mjs) and an obfuscated infostealer (Math_Symbol.js) that collects developer and cloud credentials, encrypts them, and exfiltrates them to a public GitHub repository. The attack spreads laterally by self-propagating to other packages maintained by developers whose environments were infected.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 5 extracted

Type Value Detail
Domain npm-cache[.]com Details →
Filename setup.mjs Details →
Filename Math_Symbol.js Details →
Filename math_init.js Details →
GitHub Repo Shai-Hulud Details →

MITRE ATT&CK TTPs 10 techniques