Campaigns
ChainDrop: Self-Propagating npm Supply Chain Worm Targeting Developer Credentials

ChainDrop: Self-Propagating npm Supply Chain Worm Targeting Developer Credentials Threat Campaign

ChainDropnpmSupply Chain AttackShai-HuludMini Shai-HuludTeamPCPInfostealerWormCredential TheftGitHub Account CompromiseCI/CD SecurityDeveloper ToolsBun RuntimeEthereum C2EtherHidingKeyvCacheableFlat-CacheFile-Entry-CacheDead-Man SwitchIDE PersistenceClaude CodeVS CodeAES-256-GCMRSA-OAEP
ChainDrop is a self-propagating npm supply chain worm that on 04.08.2026 poisoned 444 packages across 2,212 malicious versions representing 2 billion combined monthly downloads, after a threat actor seized the GitHub account of the keyv maintainer and injected a hybrid-encrypted infostealer - using AES-256-GCM data encryption with RSA-OAEP-SHA256 key wrapping - that spreads autonomously via stolen npm publish tokens while deliberately skipping Russian-language environments. The worm is a Mini Shai-Hulud descendant that exfiltrates developer credentials to attacker-controlled GitHub repositories

Indicators of Compromise

go.getblock.io
pypi-get.com
npm-cache.com
eth.llamarpc.com
js-mirror.com
eth-mainnet.nodereal.io

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

REMEDIATION/DETECTION

Detection strategies sourced from MITRE ATT&CK v19.1 (attack.mitre.org/detectionstrategies/) and Microsoft Security Blog (04.08.2026). OTX AlienVault: no ChainDrop-specific pulse found at time of publication (campaign too recent).


Source

Technique

Detection / Remediation Guidance

DET0009 / AN0021

T1195.001

MITRE ATT&CK v19.1 official: A package manager (npm/yarn/pnpm) downloads or restores content, writes executable or script files into project paths (node_modules), and the first execution of newly written components triggers lifecycle hooks (preinstall/postinstall) or loader scripts, followed by network egress to non-approved registries or CDNs.

DET0009 / AN0022

T1195.001

MITRE ATT&CK v19.1 official: Developer or CI invokes npm/yarn/pnpm, which writes executable or script files into PATH or project directories and immediately executes embedded lifecycle hooks (preinstall/postinstall) that spawn shells or curl/wget, followed by egress to unfamiliar registries or domains. For ChainDrop: alert on node setup.mjs followed by bun binary download from /tmp/bun-dl-*/.

DET0009 / AN0023

T1195.001

MITRE ATT&CK v19.1 official (macOS): Developer tools install or update dependencies; new Mach-O or scripts appear under ~/Library, project directories (node_modules/.bin). First run spawns sh/zsh/osascript/curl and new outbound flows; Gatekeeper/AMFI may flag unsigned components.

MITRE

T1078

Monitor for user account authentication behavior anomalies. Alert on npm publish events originating from unexpected geolocations, times, or IP ranges. Monitor GitHub repository push events and release creation for packages that lack corresponding pull requests, commits, or tags - a pattern characteristic of tarball-level injection used in ChainDrop.

MITRE

T1552.001

MITRE: Preemptively search for files containing passwords and take actions to reduce exposure. For ChainDrop detection: monitor for mass concurrent file reads across .env, .npmrc, ~/.aws/credentials, ~/.ssh, Terraform state files, and Docker registry configs - the infostealer runs ~200 glob patterns with up to 64 concurrent reads.

MITRE

T1568

Monitor DNS queries and outbound HTTPS traffic from developer workstations and CI/CD runners. Alert on eth_call requests to Ethereum RPC endpoints (eth-mainnet.nodereal.io, go.getblock.io, eth.llamarpc.com) specifically referencing contract 0xE1f2395ee43e45A1556EC6438a88c31B83493103 selector 0x53ed5143. Dynamic C2 domain retrieval via blockchain is a key differentiator of ChainDrop.

MITRE

T1119

Monitor endpoint telemetry for processes performing high-frequency, broad-pattern file reads across multiple sensitive directories in a short time window. Alert on Node.js or Bun processes accessing credential files such as .npmrc, AWS credentials, SSH keys, Kubernetes configs, and vault tokens within the same session.

MITRE

T1567.001

Monitor network traffic for HTTPS connections to npm-cache.com:443/router and unexpected GitHub API calls creating new repositories with the description "Shai-Hulud: Here We Go Again". Alert on encrypted data uploads (results-<timestamp>-<counter>.json) to public GitHub repositories from developer or CI environments.

MITRE

T1546

Monitor for modifications to .claude/settings.json and .vscode/tasks.json, particularly commits authored as [email protected] with message "chore: update config". Alert on git push events that add or modify these files in branches not matching the repository's normal release workflow.

Microsoft Defender XDR

T1195.001 / T1059.007

Microsoft Defender Antivirus detects ChainDrop as: Trojan:NPM/ShaiLoader.BY, Trojan:NPM/MalBun.A, Trojan:NPM/ShaiWorm.DAY!MTB, Behavior:Linux/SuspBunActivity.A, Behavior:Win32/SuspBunActivity.A. Defender for Endpoint: "Suspicious Node.js process behavior", "Suspicious usage of Bun runtime", "Suspicious script execution via Bun". Defender for Cloud: "Suspicious npm supply-chain compromise activity detected".

Microsoft Defender XDR

T1552 / T1119

Microsoft Defender for Endpoint hunting query for credential access: alert on gh auth token, gcloud config config-helper, az account get-access-token, or azd auth token invocations where the initiating process is bun or bun.exe with a folder path containing "bun-dl-" or node_modules.

Remediation

Post-Compromise

If a compromised package version was installed, treat the affected workstation or CI/CD runner as fully compromised. Rebuild from clean backups or from scratch. Rotate all secrets accessible from that environment: npm tokens, GitHub tokens, AWS credentials, SSH keys, Kubernetes configs, Vault tokens, Stripe/Slack/Twilio API keys. Purge npm and yarn caches. Validate that downstream build artifacts were not produced from the compromised dependency baseline.

Observed Countries250

AD (546)
AE (657)
AF (150)
AG (302)
AI (807)
AL (640)
AM (763)
AO (931)
AQ (313)
AR (587)
AS (596)
AT (195)
AU (624)
AW (662)
AX (945)
AZ (436)
BA (466)
BB (437)
BD (161)
BE (337)
BF (837)
BG (980)
BH (46)
BI (220)
BJ (285)
BL (312)
BM (673)
BN (144)
BO (231)
BQ (302)
BR (266)
BS (561)
BT (566)
BV (735)
BW (657)
BY (937)
BZ (674)
CA (317)
CC (786)
CD (633)
CF (220)
CG (684)
CH (891)
CI (804)
CK (279)
CL (54)
CM (456)
CN (263)
CO (676)
CR (416)
CU (914)
CV (43)
CW (657)
CX (740)
CY (807)
CZ (570)
DE (172)
DJ (480)
DK (3)
DM (399)
DO (384)
DZ (57)
EC (96)
EE (154)
EG (79)
EH (17)
ER (24)
ES (239)
ET (743)
FI (820)
FJ (573)
FK (776)
FM (411)
FO (871)
FR (771)
GA (609)
GB (792)
GD (853)
GE (126)
GF (239)
GG (157)
GH (316)
GI (903)
GL (164)
GM (618)
GN (151)
GP (217)
GQ (135)
GR (998)
GS (198)
GT (270)
GU (645)
GW (493)
GY (669)
HK (367)
HM (11)
HN (119)
HR (307)
HT (82)
HU (370)
ID (756)
IE (575)
IL (479)
IM (85)
IN (631)
IO (966)
IQ (466)
IR (667)
IS (81)
IT (966)
JE (469)
JM (784)
JO (698)
JP (924)
KE (898)
KG (482)
KH (119)
KI (690)
KM (341)
KN (430)
KP (858)
KR (348)
KW (716)
KY (299)
KZ (988)
LA (305)
LB (521)
LC (165)
LI (802)
LK (442)
LR (209)
LS (263)
LT (970)
LU (952)
LV (736)
LY (327)
MA (852)
MC (269)
MD (618)
ME (976)
MF (730)
MG (899)
MH (753)
MK (473)
ML (685)
MM (147)
MN (905)
MO (426)
MP (227)
MQ (720)
MR (840)
MS (638)
MT (858)
MU (665)
MV (263)
MW (415)
MX (277)
MY (810)
MZ (351)
NA (628)
NC (339)
NE (341)
NF (483)
NG (188)
NI (232)
NL (380)
NO (583)
NP (900)
NR (40)
NU (849)
NZ (362)
OM (604)
PA (682)
PE (321)
PF (881)
PG (89)
PH (9)
PK (843)
PL (641)
PM (491)
PN (406)
PR (68)
PS (40)
PT (107)
PW (609)
PY (351)
QA (703)
RE (198)
RO (57)
RS (845)
RU (914)
RW (892)
SA (598)
SB (606)
SC (979)
SD (685)
SE (658)
SG (583)
SH (334)
SI (241)
SJ (623)
SK (491)
SL (2)
SM (481)
SN (2)
SO (163)
SR (186)
SS (63)
ST (254)
SV (66)
SX (845)
SY (129)
SZ (266)
TC (704)
TD (941)
TF (299)
TG (620)
TH (791)
TJ (590)
TK (109)
TL (588)
TM (179)
TN (569)
TO (527)
TR (860)
TT (484)
TV (771)
TW (519)
TZ (791)
UA (257)
UG (1)
UM (841)
US (950)
UY (88)
UZ (136)
VA (155)
VC (796)
VE (799)
VG (65)
VI (540)
VN (4)
VU (869)
WF (405)
WS (492)
XK (160)
YE (39)
YT (176)
ZA (516)
ZM (689)
ZW (562)