Threats · 52 days ago
The danger is no longer one bad maintainer account. Stolen npm and GitHub tokens now let the payload publish its own next wave, so cleaning one package or rotating one key can feed the spread instead of stopping it. The malicious release runs during npm install, and related hooks can also fire when a repo is opened in common developer tools.
Reporting now puts the campaign at more than 2,200 malicious releases across about 440 packages, with keyv, cacheable, flat-cache, file-entry-cache, and cache-manager among the affected names. The worm steals developer and CI secrets, then uses those same credentials to backdoor more packages and repositories through trusted publishing paths.
That changes containment. If infected workstations, build runners, or repos are still able to use stolen credentials, the worm can rearm itself and keep moving through npm and GitHub workflows.
15 sources covering this story
ChainDrop: Inside a Self-Propagating npm Worm
Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing.
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages — Elastic Security Labs
Elastic Defend provides coverage for the latest npm supply chain attack.
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, Author: Renato Marinho
ChainDrop: campagna worm auto-propagante nell’ecosistema npm
Ricercatori di sicurezza hanno recentemente identificato una campagna di compromissione della supply chain software presente nell’ecosistema npm - denominata “ChainDrop” - che ha interessato oltre 400 pacchetti appartenenti a maintainer e organizzazioni differenti.
ChainDrop Worm Hits 400 npm Packages with Two Billion Monthly Installs
A new npm worm has compromised packages with over two billion monthly installs
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
ChainDrop supply chain compromise: Anatomy of a self-propagating worm | Microsoft Security Blog
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates.
Massive supply-chain attack compromises 440 packages under four hours
A self-replicating Mini Shai-Hulud worm compromised 860+ npm packages, including keyv, stealing cloud credentials and developer secrets across global environments.
ChainDrop credential stealing worm infects over 400 npm packages
The Shai Hulud variant’s blast radius includes several highly popular packages thus far..
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
A Keyv-linked npm worm poisoned 353 versions across 79 package names, stealing developer and CI credentials while repository hooks remained present.
keyv and cacheable npm Package Hijacked in Supply Chain Attack | Wiz Blog
Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages.
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
Part of the PlainSec briefing for 2026-08-07