Get alerts on this situation
We’ll email you as it develops, and you can follow the whole thread from day one.
Unsubscribe anytime.
[SITUATION] · [ACTIVE]
2 clusters · 11 sources · 5 days · First seen · Last updated
Categories: TECHNOLOGY
npm supply-chain malware attacks
Entities: Jared Wray · Keyv (npm package) · Claude Code (AI coding tool) · Tron blockchain · Socket
Overview
In late July 2026, two beta versions of npm packages under the @joyfill namespace were found to contain a remote‑access trojan. The malicious code activates on import, retrieves encrypted payloads from multiple blockchains, and can download additional code from a remote server. Security analysts linked the activity to the PolinRider threat cluster, which they suspect is part of a broader North‑Korean operation that previously ran the ViteVenom campaign.
A few days later, a far larger supply‑chain campaign emerged. Attackers compromised the GitHub account of a maintainer of the popular Keyv caching library and injected pre‑install scripts into Keyv and several related packages. The resulting ChainDrop worm downloads the Bun runtime and runs a credential‑stealer that harvests tokens and secrets from cloud services, container platforms, and development tools. The worm self‑propagates, affecting over 800 packages and receiving billions of downloads, and can change its command‑and‑control infrastructure via an Ethereum smart contract. The campaign has impacted organizations such as Deliveroo, Qlik, ServiceTitan, and Picsart and is described as a descendant of the earlier Shai‑Hulud worm.
Together, these incidents illustrate a rapid escalation in npm‑based supply‑chain attacks, moving from targeted trojan delivery to a widespread, self‑propagating worm that harvests a broad range of credentials across the software ecosystem.
Timeline
-
1 day ago
[TECHNOLOGY] 9 sourcesChainDrop npm Worm Infects Hundreds of Packages, Steals CredentialsA compromised GitHub account of Keyv maintainer Jared Wray enabled the ChainDrop npm worm to infect 868+ packages, steal cloud and AI credentials, and self‑propagate via valid GitHub Actions provenance, hitting
-
5 days ago
[TECHNOLOGY] 2 sourcesCompromised joyfill npm Packages Deliver Remote‑Access Trojan via Import in Node.jsTwo @joyfill npm beta packages were compromised, embedding import‑time code that fetches blockchain‑based payloads and installs a remote‑access trojan, linked to the PolinRider threat cluster.
Sources
borncity.com · dev.to · devops.com · hackread.com · it-boltwise.de · it-daily.net · ithome.com · kadiska.com · linux-magazin.de · solidsoftwaretools.com · thenextweb.com