Skip to main content

We've updated our Privacy Policy. Questions? Email us any time at privacy@ground.news

Published loading...Updated

ChainDrop credential stealing worm infects over 400 npm packages

Researchers said the worm used stolen tokens to republish trojanized releases and harvest npm, GitHub and cloud secrets from developers.

  • Early Tuesday, an attacker compromised a GitHub maintainer account and unleashed self-replicating malware into more than 440 distinct npm packages, according to multiple security firms.
  • The worm, built on the open-source Mini Shai-Hulud repository that TeamPCP published in May, initially launched in Keyv after the attacker hijacked the developer's GitHub account.
  • Compromised packages with over 2 billion monthly installs targeted credentials for AWS, GitHub, and AI tools including Claude Code and Gemini, researchers noted.
  • Within two hours, organizations including Deliveroo, Qlik, and ServiceTitan faced exposure. Security experts urge users to rotate credentials and audit lockfiles immediately.
  • The incident demonstrates that trusted infrastructure does not guarantee safe software when attackers weaponize legitimate build pipelines. Modern security requires runtime visibility into dependency behavior during installation.
Insights by Ground AI

23 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 86% of the sources are Center
86% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

SempreUPdate broke the news on Tuesday, August 4, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal