ChainDrop / Shai-Hulud npm Worm August 2026 — Crypto Credential Harvester
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·hjbaHp…CAU3Summary
ChainDrop is a self-propagating supply-chain worm that, on August 4, 2026, poisoned more than 444 npm packages and 2,212 package versions — representing roughly two billion monthly downloads — within a four-hour window by compromising a single high-privilege maintainer GitHub account. The payload is a multi-stage credential harvester covering cloud provider keys, developer tokens, SSH private keys, cryptocurrency wallet files (wallet.dat, Electrum), and AI-coding-tool secrets, with exfiltration endpoints resolved dynamically through an Ethereum smart contract rather than hardcoded infrastructure. ChainDrop is classified as the largest wave of the Shai-Hulud worm family, whose source code was publicly released by a group calling itself TeamPCP in May 2026, though attribution of this specific campaign remains uncertain.
Connected Entities
1 entities · 10 linked investigationsTimeline(12 events)
9 December 2025
Microsoft Security Research publishes Shai-Hulud 2.0 guidance, documenting an earlier wave of the Shai-Hulud npm supply-chain campaign.
Microsoft Security Blog11 May 2026
Microsoft Security Research identifies a new Mini Shai-Hulud resurgence compromising over 170 npm packages and two PyPI packages across 404 malicious versions.
SafeDep / Microsoft Security Research18 May 2026
A Shai-Hulud copycat worm infects at least one additional npm package, reported by The Register.
The Register22 May 2026
ChainDrop C2 infrastructure is deployed by attacker, approximately two weeks before the main attack wave.
Palo Alto Networks Unit 42June 2026
Shai-Hulud worm variant infects Red Hat npm packages downloaded approximately 80,000 times per week, reported by The Register.
The Register4 August 2026
ChainDrop attack begins at approximately 09:02 UTC with malicious commits pushed to the jaredwray GitHub account (keyv maintainer). First poisoned release keyv@6.0.0 published at 09:35 UTC.
StepSecurity / Semgrep4 August 2026
Secondary propagation wave begins at approximately 09:38 UTC using harvested npm credentials. By 13:20 UTC, 444 packages and 2,212 versions across more than a dozen organizations have been compromised.
Elastic Security Labs4 August 2026
Attackers rotate C2 exfiltration endpoints via Ethereum transaction on smart contract 0xE1f2395ee43e45A1556EC6438a88c31B83493103, adding domain awqhnjewqjkl[.]icu without modifying deployed malware.
Palo Alto Networks Unit 424 August 2026
npm begins unpublishing and reverting compromised package versions starting approximately 10:39 UTC. Elastic Security Labs identifies and reports the campaign at approximately 5:39 AM EST.
Elastic Security Labs / Semgrep4 August 2026
Microsoft Security Blog publishes 'ChainDrop supply chain compromise: Anatomy of a self-propagating worm.'
Microsoft Security Blog5 August 2026
Wiz, Palo Alto Networks Unit 42, StepSecurity, Expel, and additional security firms publish independent analyses with indicators of compromise and remediation guidance.
Wiz Blog / Unit 42 / StepSecurity5 August 2026
Cyber Security Agency of Singapore issues advisory AD-2026-009 covering the ongoing attack on keyv and related packages.
Cyber Security Agency of SingaporeDecision Log
- hash: 4ptjDzZrTTcSfmi4vFRXogzwJe8bCLv5Gui9M6mwnU9F
- hash: B7ViGuMAu8Wc299sjZnWU146pTyS8o3cec9Znrwu5YJC
- hash: J2HERHXb5hfo61TE8B1Q2SgYjX4kr7knw8PWDLCpcEtK
This investigation is cryptographically anchored to the Solana blockchain (3 events). 24 of 25 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/7/2026, 12:11:15 PM
last updated: 8/8/2026, 6:38:47 AM
4 viewsavoid.net — verified advice for a post-truth world