CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7303

As cited

Copy frozen at (site build).

threat intel

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

On August 4, 2026, Elastic Security Labs discovered that the Shai-Hulud threat actor compromised the maintainer of keyv, a popular key-value storage library with over 600 million monthly downloads. The attackers deployed CHAINDROP, a self-propagating worm that uses stolen npm credentials to inject malicious code into every package the compromised maintainer could publish, ultimately affecting over 400 npm packages. The worm steals credentials including artificial intelligence (AI) tool tokens, cloud provider keys, and npm tokens, then automatically propagates itself to other packages when it finds unprivileged npm tokens.

Why it matters: Any organization using npm packages for development faces immediate risk of trojanized dependencies; developers should revoke all GitHub and npm tokens from affected machines, implement a soak period before adopting new package versions, and rotate cloud credentials and AI tool tokens.

VendorsMicrosoftAppleGoogleAmazon Web ServicesGitHubSlackKubernetes
Actorssandworm
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary