ChainDrop / Shai-Hulud npm Worm August 2026 — Crypto Credential Harvester
Summary
ChainDrop is a self-propagating supply-chain worm that, on August 4, 2026, poisoned more than 444 npm packages and 2,212 package versions — representing roughly two billion monthly downloads — within a four-hour window by compromising a single high-privilege maintainer GitHub account. The payload is a multi-stage credential harvester covering cloud provider keys, developer tokens, SSH private keys, cryptocurrency wallet files (wallet.dat, Electrum), and AI-coding-tool secrets, with exfiltration endpoints resolved dynamically through an Ethereum smart contract rather than hardcoded infrastructure. ChainDrop is classified as the largest wave of the Shai-Hulud worm family, whose source code was publicly released by a group calling itself TeamPCP in May 2026, though attribution of this specific campaign remains uncertain.
Connected Entities
1 entities · 10 linked investigationsTimeline(12 events)
2025-12-09
Microsoft Security Research publishes Shai-Hulud 2.0 guidance, documenting an earlier wave of the Shai-Hulud npm supply-chain campaign.
Microsoft Security Blog2026-05-11
Microsoft Security Research identifies a new Mini Shai-Hulud resurgence compromising over 170 npm packages and two PyPI packages across 404 malicious versions.
SafeDep / Microsoft Security Research2026-05-18
A Shai-Hulud copycat worm infects at least one additional npm package, reported by The Register.
The Register2026-05-22
ChainDrop C2 infrastructure is deployed by attacker, approximately two weeks before the main attack wave.
Palo Alto Networks Unit 422026-06-01
Shai-Hulud worm variant infects Red Hat npm packages downloaded approximately 80,000 times per week, reported by The Register.
The Register2026-08-04
ChainDrop attack begins at approximately 09:02 UTC with malicious commits pushed to the jaredwray GitHub account (keyv maintainer). First poisoned release keyv@6.0.0 published at 09:35 UTC.
StepSecurity / Semgrep2026-08-04
Secondary propagation wave begins at approximately 09:38 UTC using harvested npm credentials. By 13:20 UTC, 444 packages and 2,212 versions across more than a dozen organizations have been compromised.
Elastic Security Labs2026-08-04
Attackers rotate C2 exfiltration endpoints via Ethereum transaction on smart contract 0xE1f2395ee43e45A1556EC6438a88c31B83493103, adding domain awqhnjewqjkl[.]icu without modifying deployed malware.
Palo Alto Networks Unit 422026-08-04
npm begins unpublishing and reverting compromised package versions starting approximately 10:39 UTC. Elastic Security Labs identifies and reports the campaign at approximately 5:39 AM EST.
Elastic Security Labs / Semgrep2026-08-04
Microsoft Security Blog publishes 'ChainDrop supply chain compromise: Anatomy of a self-propagating worm.'
Microsoft Security Blog2026-08-05
Wiz, Palo Alto Networks Unit 42, StepSecurity, Expel, and additional security firms publish independent analyses with indicators of compromise and remediation guidance.
Wiz Blog / Unit 42 / StepSecurity2026-08-05
Cyber Security Agency of Singapore issues advisory AD-2026-009 covering the ongoing attack on keyv and related packages.
Cyber Security Agency of SingaporeDecision Log
- #3review revise-12⛓ pending8/8/2026, 3:44:28 AMhash: 4ptjDzZrTTcSfmi4vFRXogzwJe8bCLv5Gui9M6mwnU9F
- #2review⛓ pending8/8/2026, 3:44:28 AMhash: B7ViGuMAu8Wc299sjZnWU146pTyS8o3cec9Znrwu5YJC
- #1publish⛓ pending8/7/2026, 12:11:26 PMhash: J2HERHXb5hfo61TE8B1Q2SgYjX4kr7knw8PWDLCpcEtK
24 of 25 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/7/2026, 12:11:15 PM
last updated: 8/8/2026, 4:12:19 AM
avoid.net — verified advice for a post-truth world