ChainDrop: Over 400 npm Packages Compromised by Self-propagating Worm, with CI/CD Credentials Used as Attack Springboard

On August 4, 2026, Microsoft Threat Intelligence disclosed the large-scale ChainDrop npm supply chain attack: more than 440 packages and over 2,200 malicious versions were released within hours, affecting high-frequency dependencies with weekly downloads exceeding 500 million times such as keyv and flat-cache. This worm is a variant of Mini Shai-Hulud. It automatically executes during npm install via the preinstall hook, steals credentials of npm/GitHub/AWS/K8s/Vault, automatically modifies tarballs for self-propagation, and can abuse GitHub Actions OIDC and inject Claude/VS Code configurations to establish persistence. This article sorts out the attack chain, IOCs, self-check methods and protection suggestions.

Read More