ChainDrop credential stealing worm infects over 400 npm packages
Researchers said the worm used stolen tokens to republish trojanized releases and harvest npm, GitHub and cloud secrets from developers.
- Early Tuesday, an attacker compromised a GitHub maintainer account and unleashed self-replicating malware into more than 440 distinct npm packages, according to multiple security firms.
- The worm, built on the open-source Mini Shai-Hulud repository that TeamPCP published in May, initially launched in Keyv after the attacker hijacked the developer's GitHub account.
- Compromised packages with over 2 billion monthly installs targeted credentials for AWS, GitHub, and AI tools including Claude Code and Gemini, researchers noted.
- Within two hours, organizations including Deliveroo, Qlik, and ServiceTitan faced exposure. Security experts urge users to rotate credentials and audit lockfiles immediately.
- The incident demonstrates that trusted infrastructure does not guarantee safe software when attackers weaponize legitimate build pipelines. Modern security requires runtime visibility into dependency behavior during installation.
23 Articles
23 Articles
New ChainDrop worm poisons over 1,300 npm packages, Keyv and Cacheable among those hit
Aikido researchers uncovers ChainDrop, a Shai‑Hulud variant infecting 1,300+ npm packages with an infostealerAttackers compromised GitHub accounts tied to popular libraries (Keyv, Cacheable, flat‑cache, file‑entry‑cache) and pushed tainted releases with 2B monthly downloadsMalware exfiltrates developer/cloud credentials and secrets to a public GitHub repo; admins should treat affected systems as compromised even after removalAnother Shai-Hulud v…
ChainDrop credential stealing worm infects over 400 npm packages
A self-propagating worm-like attack is hitting the npm registry, having infected 444 packages from more than a dozen publishers so far. The impact is massive, with the packages affected amounting to more than 2 billion monthly downloads combined. The attack began with the compromise of a GitHub account belonging to Jared Wray, who maintains Keyv, a package with over 150 million weekly downloads that provides an interface for interacting with key…
Massive supply-chain attack compromises 440 packages under four hours
In less than four hours early Tuesday, an attacker compromised a GitHub maintainer account and unleashed a self-replicating piece of malware which injected malicious code into more than 440 distinct npm packages, according to multiple security firms. The worm, built on the open-source Mini Shai-Hulud repository that TeamPCP published in May, was initially let loose in keyv, a data management interface software package with more than 600 million…
Upwind first to report malicious Keyv release that threatened thousands of JavaScript projects
For years, software supply chain attacks focused on compromising widely used applications after they had already been deployed. Increasingly, however, attackers are shifting their attention further upstream, targeting the open-source packages developers rely on every day. The latest example arrived when Upwind became the first to identify and publicly report a malicious release of the […] This story continues at The Next Web
Coverage Details
Bias Distribution
- 86% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium








