IOC Radar

Indicators are what attackers leave behind. Stolen credentials are what they arrive with.

Check Your Exposure
TLP:WHITE8 IOCs

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

MT
Microsoft Threat Intelligence
Published August 4, 2026Original Report

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTUREnpm-cache.comjs-mirror.comhttps://npm-cache.com…CAPABILITYunknownVICTIMunknown
Adversary
Infrastructure(4)
Capability
Victim

Indicators of Compromise

Indicators of Compromise8

TypeIndicatorConfidenceScoreFirst Seen
Domainnpm-cache.com
botnetintel-blogmalware
High
86
Aug 4, 26
Domainjs-mirror.com
botnetintel-blogmalware
High
86
Aug 4, 26
SHA25654dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668
file-hashintel-blogloader
High
56
Aug 5, 26
URLhttps://npm-cache.com:443/router
intel-blognetworkurl
High
58
Aug 5, 26
SHA1e1f2395ee43e45a1556ec6438a88c31b83493103
file-hashindicatorintel-blog
Medium
53
Aug 5, 26
SHA256fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb
file-hashintel-blogloader
High
59
Aug 5, 26
SHA2569fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc
file-hashintel-blogloader
High
59
Aug 5, 26
Domainpypi-get.com
botnetintel-blogmalware
High
86
Aug 4, 26

IOC Relationship Graph

IOC Relationship Graph8 total IOCs
DomainSHA256URLSHA1
Domain3SHA2563URL1SHA11REPORTChainDrop supply chain com
scroll to zoom · drag to pan · click IOC to open