Close Menu
NCIJ Network NCIJ Network
    What's Hot

    James Talarico’s Voter Registration Is Raising Questions as He Hits at Ken Paxton — ProPublica

    August 5, 2026

    North Sea oil is a litmus test for Burnham | Oil

    August 5, 2026

    Trump spent $5M in taxpayer funds to restore horse statues, coat them in gold

    August 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • James Talarico’s Voter Registration Is Raising Questions as He Hits at Ken Paxton — ProPublica
    • North Sea oil is a litmus test for Burnham | Oil
    • Trump spent $5M in taxpayer funds to restore horse statues, coat them in gold
    • Migrant Crisis Reveals Vast Differences Between Ceuta and Its Moroccan Neighbor
    • Das Phantom Tom Rohrböck – POLITICO
    • Rep. Chuck Edwards Drops Re-election Bid in North Carolina After Ethics Rebuke
    • High-stakes Michigan Democratic Senate primary too close to call
    • The best 98-inch TVs of 2026: Expert tested
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 5
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 5, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    More than 2,200 malicious versions of 440 packages were published to the NPM registry as part of a fresh Mini Shai-Hulud supply chain attack.

    Dubbed ChainDrop, the campaign started with 11 malware carriers in the keyv and cacheable namespaces, after their maintainer’s GitHub account was compromised.

    Combined, the infected packages have over 500 million weekly downloads. They are widely used across the ecosystem and their poisoning led to 433 additional packages being infected.

    Similar to previous Mini Shai-Hulud attacks, the infected packages executed malicious code during installation, dropping an information stealer with self-propagation functionality.

    On the infected machines, the malware targets all the secrets it can find, encrypts them, and then exfiltrates the data either to a dynamic HTTPS endpoint or to attacker-created public GitHub repositories that have the ‘Shai-Hulud: Here We Go Again’ description.

    “Once executed, the malware searches developer workstations and continuous integration and continuous delivery (CI/CD) environments for NPM, GitHub, cloud, and infrastructure credentials. It uses recovered identities to authenticate to NPM, GitHub, Amazon Web Services (AWS), Kubernetes, and HashiCorp Vault, enabling it to enumerate packages, repositories, workflow secrets, cloud parameters, and secret-store values,” Microsoft explains.

    Advertisement. Scroll to continue reading.

    Additionally, the malware uses the stolen NPM credentials to publish poisoned versions of every package it can reach on the infected machine, and leverages compromised GitHub credentials and GitHub Actions to infect more repositories for credential theft, JFrog says.

    “After obtaining an NPM publishing token, it enumerates packages available to the compromised identity, downloads their latest tarballs, inserts the malware and setup loader, adds a preinstall hook, increments the patch version, and republishes the modified packages. The malware can also use stolen GitHub credentials to inject Claude and Visual Studio Code configuration files into repositories, establishing persistence and creating an additional developer-to-developer infection path,” Microsoft notes.

    Because the malware republished many historical versions of the compromised packages, the total number of malicious package iterations observed on August 4 reached 2,212 in under four hours, StepSecurity says.

    All infected package versions contained a preinstall dropper designed to download the legitimate Bun JavaScript runtime alongside 710 KB of obfuscated second-stage code representing the actual malware.

    An evolved descendant of the Shai-Hulud 2.0 worm, the malware uses an Ethereum blockchain for command-and-control (C&C), a technique called EtherHiding.

    The worm also installs a host-level dead-man’s switch: after achieving persistence on macOS and Linux, it polls the GitHub API using the victim’s stolen GitHub token every 60 seconds, and deletes its state and exits if the token stops working. It also self-clears after 24 hours, Socket notes.

    NPM developers who installed any of the infected package versions should consider their machines compromised. They are advised to remove the malware, rebuild CI runners and build machines, revoke and rotate potentially compromised credentials, and audit their GitHub repositories for anomalous activity.

    “Isolate affected systems. Preserve package tarballs, npm logs, CI logs, GitHub audit logs, and runner images before cleanup. You will need them to bound the exposure window,” JFrog recommends.

    Related: New GitHub, PyPI Policies Boost Supply Chain Security

    Related: US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security

    Related: Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains

    Related: Multiple Jscrambler Packages Impacted by Supply Chain Attack

    attack chain ChainDrop infected npm Packages supply
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    One C2 kit. 30 customers. 2 governments

    Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

    New XCSSET variant targets macOS devs via compromised Xcode projects

    QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

    Zenity Raises $125 Million in Series C Funding

    Murderous heat, an endangered food supply and no net zero: this is the life the radical right wants you to have | George Monbiot

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    James Talarico’s Voter Registration Is Raising Questions as He Hits at Ken Paxton — ProPublica

    August 5, 2026

    North Sea oil is a litmus test for Burnham | Oil

    August 5, 2026

    Trump spent $5M in taxpayer funds to restore horse statues, coat them in gold

    August 5, 2026

    Migrant Crisis Reveals Vast Differences Between Ceuta and Its Moroccan Neighbor

    August 5, 2026
    Latest Posts

    Oil prices hit $100 for the first time since May

    July 23, 2026

    Pew Survey: China May Be Liked More, but It Is Celebrating a Race It Never Ran

    July 23, 2026

    Yinson Production and PTSC’s FSO heads off to Southeast Asian oil project

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    James Talarico’s Voter Registration Is Raising Questions as He Hits at Ken Paxton — ProPublica

    August 5, 2026

    North Sea oil is a litmus test for Burnham | Oil

    August 5, 2026

    Trump spent $5M in taxpayer funds to restore horse statues, coat them in gold

    August 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.