ChainDrop Worm Infects 1,300+ npm Packages With Credential-Stealing Malware
Executive Briefing
- Aikido researchers identified ChainDrop, a Shai-Hulud variant compromising 868 packages across 1,381 versions on npm.
- Attackers breached GitHub accounts tied to Keyv and Cacheable, libraries with 2 billion combined monthly downloads.
- Malware steals AWS credentials, GitHub tokens, Kubernetes secrets, and npm tokens, sending them to a public GitHub repo.
- Affected organizations include Deliveroo, Picsart, Qlik, and ServiceTitan via downstream package dependencies.
- Researchers warn admins to treat any system that installed a tainted package as fully compromised, even post-removal.
- Shai-Hulud source code was publicly released in May 2026 by TeamPCP, enabling multiple copycat campaigns like ChainDrop.
Sponsored