Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The king who outfoxed Pedro Sánchez

    August 4, 2026

    How an OpenAI influencer trip backfired 

    August 4, 2026

    Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer

    August 4, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The king who outfoxed Pedro Sánchez
    • How an OpenAI influencer trip backfired 
    • Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer
    • HYPE ETFs see $29.8M outflow drought as flows stay positive
    • Emperor penguin chicks like these starved. An iceberg may be the cause
    • Scientists discover that giant octopuses were top predators of ancient oceans
    • Asso.subsea revealed as buyer of Reach Subsea and Eidesvik’s IMR vessel
    • Democrats for 8th Congressional District seat argue they’re the party’s best shot
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 4
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Massive ChainDrop npm supply-chain attack infects hundreds of packages

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 4, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Self-propagating malware named ‘ChainDrop’ has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.

    Infected packages include very popular ones such as Keyv and Cacheable, flat-cache and file-entry-cache, all caching utilities from the same maintainer. 

    The supply-chain attack started after the threat actor compromised the GitHub account of Keyv’s maintainer, and quickly spread to packages associated with major organizations such as Deliveroo, Ornikar, OneReach, Picsart, Qlik, and ServiceTitan.

    image

    Multiple application security companies spotted the attack and discovered that it deployed a Shai-Hulud-based worm named ChainDrop.

    A report from Aikido says “at least 868 packages (across 1381 versions) have been compromised by the worm.” 

    The researchers say that the attacker pushed malicious files directly to the projects’ main branches and then generated new package releases.

    Because the packages were built and published through their legitimate GitHub Actions workflows, the compromised npm releases carried valid provenance information.

    The poisoned packages contain two files: the setup.mjs payload dropper and the Math_Symbol.js script for stealing sensitive information, as well as a "preinstall": "node setup.mjs" entry in their package.json configuration file.

    “Anyone who ran npm install against an affected version would have had setup.mjs execute automatically before their install completed,” Aikido researchers warn.

    The setup.mjs dropper downloads the Bun JavaScript runtime from the official GitHub release to execute Math_Symbol.js, the malicious payload with infostealing capabilities.

    
    execFileSync(, ['/Math_Symbol.js'], {
      stdio: 'inherit',
      cwd: 
    })

    After downloading the Bun executable to run the infostealer script, setup.mjs deletes the temporary runtime directory.

    Aikido notes that the infostealer collects developer and cloud credentials from the compromised environment and encrypts them before sending them to a public GitHub repository with the description “Shai-Hulud: Here We Go Again.”

    The malicious JavaScript is heavily obfuscated and includes self-spreading capabilities that allow it to infect packages from other maintainers that used a previously compromised package.

    While Aikido found that the Bun executable launched the Math_Symbol.js script, BleepingComputer has also seen compromised npm packages containing the math_init.js script.

    Obfuscated math_init.js / Math_Symbol.js script
    Obfuscated math_init.js / Math_Symbol.js script
    source: BleepingComputer

    Every token is first validated in real-time against registry.npmjs[.]org/-/whoami before being stolen.

    The malware searches infected development systems and CI/CD runners for credentials that could grant it access to additional source code repositories and npm packages, and collects the following types of data:

    • The complete process environment.
    • Local configuration and credential files.
    • GitHub PATs, workflow tokens, and other ghp_, gho_, and ghs_ tokens.
    • npm tokens beginning with npm_.
    • GitHub Actions secrets, including code designed to extract "isSecret":true values from a self-hosted runner.
    • AWS credentials, SSM Parameter Store values using WithDecryption: true, and Secrets Manager secrets.
    • Kubernetes secrets from accessible namespaces.
    • HashiCorp Vault tokens and KV secrets.
    • Database credentials, private keys, Stripe, Slack, Twilio, Azure, and GCP credentials.

    According to cloud security company Wiz, the ‘npm-cache[.]com’ domain is also being used for exfiltrating data and should be treated as a strong indicator of compromise.

    If an affected package version was installed, system administrators should treat the developer workstation or CI/CD runner as compromised even if the package was subsequently removed.

    In such instances, it is recommended to rebuild systems from safe backups or from scratch, rotate all tokens that were accessible from the impacted environment, and review logs for unauthorized access and repositories for unexpected commits or changes.

    As the attack is still unfolding, the number of packages and exact malicious versions is expected to grow, so it is important to continue using dependency allowlisting, integrity checks, and provenance controls.

    A list of compromised npm packages is available from Wiz, StepSecurity, Aikido, Socket, and Ox Security. The security companies also provide a list of indicators of compromise that include hashes for malicious files and artifacts, and network data.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    attack ChainDrop hundreds infects massive npm Packages supplychain
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer

    Video shows Russian drone chasing Ukrainian street vendor in ‘human safari’ attack

    Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)

    Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

    Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

    The Minnesota attackers may hold a better backup of your plant than you do

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The king who outfoxed Pedro Sánchez

    August 4, 2026

    How an OpenAI influencer trip backfired 

    August 4, 2026

    Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer

    August 4, 2026

    HYPE ETFs see $29.8M outflow drought as flows stay positive

    August 4, 2026
    Latest Posts

    Oil prices hit $100 for the first time since May

    July 23, 2026

    Pew Survey: China May Be Liked More, but It Is Celebrating a Race It Never Ran

    July 23, 2026

    Yinson Production and PTSC’s FSO heads off to Southeast Asian oil project

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The king who outfoxed Pedro Sánchez

    August 4, 2026

    How an OpenAI influencer trip backfired 

    August 4, 2026

    Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer

    August 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.