unit42 · Crawled Aug 7, 2026
ChainDrop: Inside a Self-Propagating npm Worm
18 IoCs 1 Malware
Read original article ↗
AI Summary
ChainDrop is a self-propagating npm worm that infected over 400 packages, including widely used ones like keyv and cacheable-request, enabling it to steal cloud credentials, npm and GitHub tokens, SSH keys, and other sensitive developer data. The worm uses a combination of domain-based and GitHub-based exfiltration, with C2 infrastructure resolved via an Ethereum smart contract, allowing silent domain rotation through blockchain transactions. It establishes persistence through VS Code and Claude Code configurations, targets CI runners to extract ephemeral OIDC tokens, and can republish infected packages while preserving legitimate functionality, making detection difficult.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 18 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | npm-cache[.]com | Details → |
| Domain | pypi-get[.]com | Details → |
| Domain | js-mirror[.]com | Details → |
| Domain | awqhnjewqjkl[.]icu | Details → |
| IP | 104[.]21[.]91[.]101 | Details → |
| IP | 172[.]67[.]215[.]154 | Details → |
| SHA-256 | 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc | Details → |
| SHA-256 | 54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668 | Details → |
| SHA-256 | fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb | Details → |
| SHA-256 | b27b82afa5f15512f3856e549fb83d873fd0049759a4b62ce64c8d7d4dc2c678 | Details → |
| Filename | math_init.js | Details → |
| Filename | Math_Symbol.js | Details → |
| Filename | setup.mjs | Details → |
| Filename | .vscode/tasks.json | Details → |
| Filename | .claude/settings.json | Details → |
| Filename | .github/workflows/codeql_analysis.yml | Details → |
| GitHub Repo | thebeautifulmarchoftime | Details → |
| Registry User | IfYouBlockThisAPIKeyItWillCrashTheLiveProductionServersOfAllThirdPartyClients | Details → |
MITRE ATT&CK TTPs 19 techniques
T1021.003 Distributed Component Object Model · Lateral Movement T1059.001 PowerShell · Execution T1059.007 JavaScript · Execution T1071 Application Layer Protocol · Command And Control T1071.003 Mail Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1081 T1081 T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1133 External Remote Services · Persistence T1195 Supply Chain Compromise · Initial Access T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1485 Data Destruction · Impact T1528 Steal Application Access Token · Credential Access T1530 Data from Cloud Storage · Collection T1552 Unsecured Credentials · Credential Access T1553 Subvert Trust Controls · Defense Evasion T1555 Credentials from Password Stores · Credential Access T1566 Phishing · Initial Access