unit42 · Crawled Aug 7, 2026

ChainDrop: Inside a Self-Propagating npm Worm

18 IoCs 1 Malware
Read original article ↗

AI Summary

ChainDrop is a self-propagating npm worm that infected over 400 packages, including widely used ones like keyv and cacheable-request, enabling it to steal cloud credentials, npm and GitHub tokens, SSH keys, and other sensitive developer data. The worm uses a combination of domain-based and GitHub-based exfiltration, with C2 infrastructure resolved via an Ethereum smart contract, allowing silent domain rotation through blockchain transactions. It establishes persistence through VS Code and Claude Code configurations, targets CI runners to extract ephemeral OIDC tokens, and can republish infected packages while preserving legitimate functionality, making detection difficult.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 18 extracted

Type Value Detail
Domain npm-cache[.]com Details →
Domain pypi-get[.]com Details →
Domain js-mirror[.]com Details →
Domain awqhnjewqjkl[.]icu Details →
IP 104[.]21[.]91[.]101 Details →
IP 172[.]67[.]215[.]154 Details →
SHA-256 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc Details →
SHA-256 54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668 Details →
SHA-256 fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb Details →
SHA-256 b27b82afa5f15512f3856e549fb83d873fd0049759a4b62ce64c8d7d4dc2c678 Details →
Filename math_init.js Details →
Filename Math_Symbol.js Details →
Filename setup.mjs Details →
Filename .vscode/tasks.json Details →
Filename .claude/settings.json Details →
Filename .github/workflows/codeql_analysis.yml Details →
GitHub Repo thebeautifulmarchoftime Details →
Registry User IfYouBlockThisAPIKeyItWillCrashTheLiveProductionServersOfAllThirdPartyClients Details →

MITRE ATT&CK TTPs 19 techniques