ChainDrop / Mini Shai-Hulud npm Supply Chain Worm (August 2026)
Summary
ChainDrop is a self-propagating npm supply chain worm discovered on August 4, 2026, representing the latest wave of the Mini Shai-Hulud malware family attributed to the threat group TeamPCP. By compromising the GitHub account of open-source maintainer Jared Wray (jaredwray), attackers injected a two-stage credential-harvesting payload into the widely used keyv and cacheable package ecosystems, which then self-propagated to over 440 additional npm packages representing approximately 2 billion combined monthly downloads. A distinguishing technical characteristic is the worm's use of an Ethereum smart contract for dynamic command-and-control infrastructure, a technique known as EtherHiding, which explicitly targets crypto and Web3 developer tooling alongside cloud and CI/CD credentials.
Connected Entities
1 entities · 10 linked investigationsTimeline(13 events)
2025-09-01
Original Shai-Hulud worm debuts, attributed to TeamPCP (UNC6780); marks start of systematic npm/PyPI supply chain campaign.
Tenable Mini Shai-Hulud FAQ2026-04-01
Mini Shai-Hulud (fourth generation) begins operations, introducing SLSA provenance attestation forgery, OIDC token extraction from runner memory, and AI agent persistence hooks.
Tenable Mini Shai-Hulud FAQ2026-05-11
TanStack attack: TeamPCP compromises GitHub Actions pipeline, publishes 84 malicious versions across 42 @tanstack/* packages in approximately six minutes. CVE-2026-45321 (CVSS 9.6) assigned.
StepSecurity - TeamPCP Mini Shai-Hulud TanStack2026-05-12
TeamPCP open-sources Shai-Hulud worm on GitHub under MIT License with message 'Shai-Hulud: Open Sourcing The Carnage,' announces $1,000 contest for largest supply chain attack using the code.
Akamai - Mini Shai-Hulud: The Worm Returns and Goes Public2026-05-19
@antv ecosystem attack: 639 malicious versions across 323 packages published in under 30 minutes via stolen maintainer account. Socket detects most within 6.7 minutes.
SafeDep - Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised2026-08-04
ChainDrop wave begins: attacker uses compromised GitHub account of maintainer jaredwray to push poisoned commit (ee2681a) to keyv monorepo at 09:02:37 UTC, injecting setup.mjs and Math_Symbol.js.
StepSecurity - ChainDrop npm Worm2026-08-04
09:35 UTC: keyv@6.0.0 published via OIDC trusted publishing with valid SLSA attestation. First public security warnings appear at approximately 10:18-10:20 UTC.
Snyk - Inside the keyv npm Supply Chain Compromise2026-08-04
09:38 UTC onward: automated second-wave propagation begins, with the worm using harvested npm credentials to infect 433 additional packages across @servicetitan, @onereach, @or-sdk, @ornikar, and 10+ other namespaces. 2,212 total malicious versions published within four hours.
StepSecurity - ChainDrop npm Worm2026-08-04
10:39 UTC: npm begins unpublishing affected versions. Cleanup substantially complete by 18:10 UTC.
StepSecurity - ChainDrop npm Worm2026-08-04
Microsoft Security Blog publishes primary technical analysis by Ravikant Tiwari, Sagar Patil, and Suriyaraj Natarajan.
Microsoft Security Blog - ChainDrop supply chain compromise2026-08-04
Jared Wray (jaredwray) confirms via X that his GitHub account was compromised; reports using OIDC with npm and one-time codes. States he regained account access at approximately 20:00 UTC and began full audit.
BleepingComputer - ChainDrop npm supply-chain attackDecision Log
- #1publish⛓ pending8/6/2026, 11:42:14 PMhash: 99w2fB6zyqQq1ZGtgViN5TqBgti1TwRyY1o1W8o8j7hN
24 of 26 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/6/2026, 11:42:00 PM
last updated: 8/7/2026, 4:14:43 AM
avoid.net — verified advice for a post-truth world