# npm supply-chain malware attacks

> Live situation record from CLSTR: https://clstr.news/situations/npm-supply-chain-malware-attacks
> Updated: 2026-08-04T09:30:01.000Z. Sources: 11. Developments: 2.

In late July 2026, two beta versions of npm packages under the @joyfill namespace were found to contain a remote‑access trojan. The malicious code activates on import, retrieves encrypted payloads from multiple blockchains, and can download additional code from a remote server. Security analysts linked the activity to the PolinRider threat cluster, which they suspect is part of a broader North‑Korean operation that previously ran the ViteVenom campaign.

A few days later, a far larger supply‑chain campaign emerged. Attackers compromised the GitHub account of a maintainer of the popular Keyv caching library and injected pre‑install scripts into Keyv and several related packages. The resulting ChainDrop worm downloads the Bun runtime and runs a credential‑stealer that harvests tokens and secrets from cloud services, container platforms, and development tools. The worm self‑propagates, affecting over 800 packages and receiving billions of downloads, and can change its command‑and‑control infrastructure via an Ethereum smart contract. The campaign has impacted organizations such as Deliveroo, Qlik, ServiceTitan, and Picsart and is described as a descendant of the earlier Shai‑Hulud worm.

Together, these incidents illustrate a rapid escalation in npm‑based supply‑chain attacks, moving from targeted trojan delivery to a widespread, self‑propagating worm that harvests a broad range of credentials across the software ecosystem.

## Timeline

### 2026-08-04: ChainDrop npm Worm Infects Hundreds of Packages, Steals Credentials

A compromised GitHub account of Keyv maintainer Jared Wray enabled the ChainDrop npm worm to infect 868+ packages, steal cloud and AI credentials, and self‑propagate via valid GitHub Actions provenance, hitting

9 sources. https://clstr.news/cluster/keyv-linked-npm-worm-hijacks-claude-code-and-vs-code-spreads-across-hundreds-of-packages

### 2026-07-31: Compromised joyfill npm Packages Deliver Remote‑Access Trojan via Import in Node.js

Two @joyfill npm beta packages were compromised, embedding import‑time code that fetches blockchain‑based payloads and installs a remote‑access trojan, linked to the PolinRider threat cluster.

2 sources. https://clstr.news/cluster/compromised-joyfill-npm-packages-deliver-remoteaccess-trojan-via-import-in-nodejs

---
Cite as: npm supply-chain malware attacks. CLSTR, https://clstr.news/situations/npm-supply-chain-malware-attacks
