< Back to all clusters
[TECHNOLOGY] · United States, United Kingdom, Germany, China · 9 sources

ChainDrop npm Worm Infects Hundreds of Packages, Steals Credentials

In early August 2026 a large‑scale software supply‑chain attack compromised the GitHub account of Jared Wray, maintainer of the popular JavaScript caching library Keyv. Attackers added malicious pre‑install scripts to Keyv and related packages (flat‑cache, file‑entry‑cache, cacheable, etc.) and used the projects’ legitimate GitHub Actions pipelines to publish poisoned versions to the npm registry. The payload downloads the Bun JavaScript runtime, then runs an obfuscated credential‑stealer that harvests tokens and secrets from GitHub, npm, AWS, Azure, Google Cloud, Kubernetes, HashiCorp Vault, SSH keys, database credentials and AI‑tool logins. Stolen tokens are used to self‑propagate the worm to other packages, resulting in at least 868 affected packages and 1,381 malicious versions, collectively receiving more than two billion monthly downloads. Some variants resolve command‑and‑control hosts via an Ethereum smart contract, allowing the attacker to change infrastructure without republishing packages. The infection spread to software used by organizations such as Deliveroo, Qlik, ServiceTitan, Picsart and others. Researchers from Aikido Security, StepSecurity, BleepingComputer and others documented the campaign, naming it ChainDrop, a descendant of the earlier Shai‑Hulud worm.

Entities: ChainDrop · Claude Code (AI coding tool) · GitHub · Jared Wray · Keyv · Keyv (npm package) · Visual Studio Code · npm