As cited
Copy frozen at (site build).
threat intel
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
On August 4, 2026, Elastic Security Labs discovered that the Shai-Hulud threat actor compromised the maintainer of keyv, a popular key-value storage library with over 600 million monthly downloads. The attackers deployed CHAINDROP, a self-propagating worm that uses stolen npm credentials to inject malicious code into every package the compromised maintainer could publish, ultimately affecting over 400 npm packages. The worm steals credentials including artificial intelligence (AI) tool tokens, cloud provider keys, and npm tokens, then automatically propagates itself to other packages when it finds unprivileged npm tokens.
Why it matters: Any organization using npm packages for development faces immediate risk of trojanized dependencies; developers should revoke all GitHub and npm tokens from affected machines, implement a soak period before adopting new package versions, and rotate cloud credentials and AI tool tokens.
- Source published
- First seen by Cybersecurity Tracker