CYBERSECURITYTRACKER
TRACKING7,159 stories in this site build1,507 vulnerability news stories in this site build
Permanent story citation

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3863

As cited

Copy frozen at (site build).

threat intel

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting over 400 packages across multiple publishers, delivering a self-propagating credential-stealing worm called Mini Shai-Hulud through obfuscated JavaScript payloads. The malware executes via npm preinstall hooks before package installation completes, searches for and exfiltrates npm, GitHub, AWS, Kubernetes, and vault credentials, then automatically republishes compromised packages to propagate itself. Organizations using affected packages should treat developer workstations and CI/CD systems as potentially compromised and immediately revoke and rotate all exposed credentials.

Why it matters: Any organization using npm packages from affected publishers risks credential theft, unauthorized package republication, and supply chain propagation; immediate action to identify installed versions, audit credential exposure, and rebuild systems from trusted sources is required.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

Microsoft Threat Intelligence identified a large-scale npm supply chain attack compromising over 400 packages through malicious patch releases containing a self-propagating worm variant called Mini Shai-Hulud. The obfuscated JavaScript payload executes via npm preinstall hooks, harvests credentials from developer machines and CI/CD environments, and automatically republishes infected packages to amplify the attack across the ecosystem. Affected organizations should treat compromised workstations and build systems as breached and immediately revoke credentials, rotate secrets, and rebuild artifacts from trusted sources.

Why it matters: Any organization using affected npm packages (keyv, flat-cache, cache-manager, and hundreds of others) with lifecycle scripts enabled faces immediate credential theft and supply chain propagation risk; prioritize detecting unauthorized package releases, repository modifications, and credential exfiltration.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

Microsoft Threat Intelligence identified a large-scale npm supply chain attack compromising over 400 packages through malicious patch releases containing a self-propagating worm variant called Mini Shai-Hulud. The obfuscated JavaScript payload executes via npm preinstall hooks, harvests credentials from developer machines and CI/CD environments, and automatically republishes infected packages to amplify the attack across the ecosystem. Affected organizations should treat compromised workstations and build systems as breached and immediately revoke credentials, rotate secrets, and rebuild artifacts from trusted sources.

Why it matters: Any organization using affected npm packages (keyv, flat-cache, cache-manager, and hundreds of others) with lifecycle scripts enabled faces immediate credential theft and supply chain propagation risk; prioritize detecting unauthorized package releases, repository modifications, and credential exfiltration.

VendorsMicrosoftAmazon Web ServicesGitHubKubernetes
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary