Skip to main content
AVOID.NET

ChainDrop / Mini Shai-Hulud npm Supply Chain Worm (August 2026)

avoid.net/chaindrop-mini-shai-hulud-npm-supply-chain-worm-august-20260/100·95% conf.
[VERIFIED]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·5pyhc2…UJy8

Summary

ChainDrop is a self-propagating npm supply chain worm discovered on August 4, 2026, representing the latest wave of the Mini Shai-Hulud malware family attributed to the threat group TeamPCP. By compromising the GitHub account of open-source maintainer Jared Wray (jaredwray), attackers injected a two-stage credential-harvesting payload into the widely used keyv and cacheable package ecosystems, which then self-propagated to over 440 additional npm packages representing approximately 2 billion combined monthly downloads. A distinguishing technical characteristic is the worm's use of an Ethereum smart contract for dynamic command-and-control infrastructure, a technique known as EtherHiding, which explicitly targets crypto and Web3 developer tooling alongside cloud and CI/CD credentials.

Connected Entities

6 entities · 60 linked investigations
Relationships
  • ChainDrop / Mini Shai-Hulud npm Supply Chain Worm (August 2026)mentioned withMonero(70%)
  • ChainDrop / Mini Shai-Hulud npm Supply Chain Worm (August 2026)mentioned withSolana(60%)
  • ChainDrop / Mini Shai-Hulud npm Supply Chain Worm (August 2026)mentioned withEthereum(80%)
  • ChainDrop / Shai-Hulud npm Worm August 2026 — Crypto Credential Harvestermentioned withEthereum(70%)
  • ChainDrop / Shai-Hulud npm Worm August 2026 — Crypto Credential Harvestermentioned withChainDrop / Mini Shai-Hulud npm Supply Chain Worm (August 2026)(70%)
  • Solanamentioned withEthereum(60%)
  • Shai-Hulud / TeamPCP Supply Chain Attackmentioned withEthereum(60%)
  • Shai-Hulud / TeamPCP Supply Chain Attackmentioned withSolana(60%)
  • ChainDrop / Shai-Hulud npm Worm August 2026 — Crypto Credential Harvestermentioned withShai-Hulud / TeamPCP Supply Chain Attack(70%)
  • ChainDrop / Mini Shai-Hulud npm Supply Chain Worm (August 2026)mentioned withShai-Hulud / TeamPCP Supply Chain Attack(70%)
  • + 1 more
Have evidence about ChainDrop / Mini Shai-Hulud npm Supply Chain Worm (August 2026)?

Timeline(13 events)

September 2025

Original Shai-Hulud worm debuts, attributed to TeamPCP (UNC6780); marks start of systematic npm/PyPI supply chain campaign.

Tenable Mini Shai-Hulud FAQ

November 2025

SHA1-Hulud variant introduced with enhanced capabilities.

Tenable Mini Shai-Hulud FAQ

March 2026

SANDWORM_MODE iteration of the worm introduced.

Tenable Mini Shai-Hulud FAQ

April 2026

Mini Shai-Hulud (fourth generation) begins operations, introducing SLSA provenance attestation forgery, OIDC token extraction from runner memory, and AI agent persistence hooks.

Tenable Mini Shai-Hulud FAQ

11 May 2026

TanStack attack: TeamPCP compromises GitHub Actions pipeline, publishes 84 malicious versions across 42 @tanstack/* packages in approximately six minutes. CVE-2026-45321 (CVSS 9.6) assigned.

StepSecurity - TeamPCP Mini Shai-Hulud TanStack

12 May 2026

TeamPCP open-sources Shai-Hulud worm on GitHub under MIT License with message 'Shai-Hulud: Open Sourcing The Carnage,' announces $1,000 contest for largest supply chain attack using the code.

Akamai - Mini Shai-Hulud: The Worm Returns and Goes Public

19 May 2026

@antv ecosystem attack: 639 malicious versions across 323 packages published in under 30 minutes via stolen maintainer account. Socket detects most within 6.7 minutes.

SafeDep - Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised

4 August 2026

ChainDrop wave begins: attacker uses compromised GitHub account of maintainer jaredwray to push poisoned commit (ee2681a) to keyv monorepo at 09:02:37 UTC, injecting setup.mjs and Math_Symbol.js.

StepSecurity - ChainDrop npm Worm

4 August 2026

09:35 UTC: keyv@6.0.0 published via OIDC trusted publishing with valid SLSA attestation. First public security warnings appear at approximately 10:18-10:20 UTC.

Snyk - Inside the keyv npm Supply Chain Compromise

4 August 2026

09:38 UTC onward: automated second-wave propagation begins, with the worm using harvested npm credentials to infect 433 additional packages across @servicetitan, @onereach, @or-sdk, @ornikar, and 10+ other namespaces. 2,212 total malicious versions published within four hours.

StepSecurity - ChainDrop npm Worm

4 August 2026

10:39 UTC: npm begins unpublishing affected versions. Cleanup substantially complete by 18:10 UTC.

StepSecurity - ChainDrop npm Worm

4 August 2026

Microsoft Security Blog publishes primary technical analysis by Ravikant Tiwari, Sagar Patil, and Suriyaraj Natarajan.

Microsoft Security Blog - ChainDrop supply chain compromise

4 August 2026

Jared Wray (jaredwray) confirms via X that his GitHub account was compromised; reports using OIDC with npm and one-time codes. States he regained account access at approximately 20:00 UTC and began full audit.

BleepingComputer - ChainDrop npm supply-chain attack
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 26 of 26 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/6/2026, 11:42:00 PM

last updated: 8/15/2026, 4:54:02 AM

4 views

avoid.net — verified advice for a post-truth world