# One Compromised Maintainer Account. 440 Infected Packages. 500 Million Weekly Downloads.
The arithmetic of a supply chain attack is always brutal, but ChainDrop makes the math especially uncomfortable. A single GitHub account belonging to a package maintainer in the keyv and cacheable namespaces was compromised. Eleven packages got poisoned. Within four hours on August 4, 2,212 malicious package versions had been published to the NPM registry — and 433 additional packages caught the infection, not from the original attacker, but from other developers who installed the poisoned dependencies.
This is what a self-replicating supply chain worm looks like in the wild.
## How the Propagation Loop Worked
ChainDrop is a descendant of the Shai-Hulud worm family, and it improves on its predecessors in several meaningful ways. The core mechanism is deceptively elegant: the malware executes during npm install via a preinstall hook, drops a second-stage payload (710KB of obfuscated code bundled with a legitimate Bun JavaScript runtime), and immediately starts hunting for credentials on the infected machine.
The credential sweep is comprehensive. Developer workstations and CI/CD runners get scoured for NPM publishing tokens, GitHub personal access tokens, AWS credentials, Kubernetes configs, and HashiCorp Vault secrets. Once it has an NPM token, the malware enumerates every package that token can publish to, downloads the latest tarballs, splices in its own dropper, increments the patch version number (so it looks like a legitimate release), and republishes. Every package a compromised developer maintained or had publish rights to becomes a vector.
The GitHub credential path is equally damaging. Stolen tokens get used to inject malicious GitHub Actions workflows — and, notably, to plant both Claude and Visual Studio Code configuration files into repositories. That last detail deserves attention: the malware is deliberately targeting the developer tooling layer, creating an infection path that moves from developer to developer through shared repos and IDE configs rather than just through package installs.
## Blockchain C&C and a Built-In Evidence Shredder
ChainDrop's command-and-control infrastructure uses EtherHiding — routing C&C communications through the Ethereum blockchain. This technique, originally observed in cryptojacking campaigns, has graduated to serious credential-theft malware. The appeal is obvious: you can't sinkhole a blockchain, there's no C&C domain to take down, and the traffic blends with routine crypto wallet interactions on a network monitor that isn't specifically watching for it.
The malware also exfiltrates to attacker-created public GitHub repositories labeled with the description "Shai-Hulud: Here We Go Again" — brazenly transparent naming that doubles as operational trolling.
Perhaps the most forensically problematic feature is the dead-man's switch. After establishing persistence on macOS and Linux, the worm polls the GitHub API every 60 seconds using the victim's stolen token. If that token stops working — revoked, rotated, or otherwise invalidated — the malware deletes its state and exits. It also hard-wipes itself after 24 hours regardless. For incident responders trying to establish exposure windows, this is a deliberate attack on the evidence trail. JFrog's advice to preserve package tarballs, NPM logs, CI logs, and GitHub audit logs before beginning cleanup isn't just good practice — it's the only way to bound what actually got touched before the malware erased itself.
## What Forensics Looks Like When the Evidence Expires
The 24-hour self-destruct creates a specific operational problem: if your monitoring didn't catch the installation event in real time, and you're investigating 36 hours later, the malware may already be gone while the credentials it stole are still being actively used. The absence of the malware on a machine does not mean the machine is clean. It may mean you're late.
The affected keyv and cacheable packages carry significant download weight — combined, packages in these namespaces see over 500 million weekly downloads. These aren't fringe packages used by hobbyists. They're infrastructure code sitting inside monorepos at mid-size startups, enterprise build pipelines, and CI runners that have been granted cloud credentials to deploy production services.
For any developer who ran `npm install` on August 4 or installed package updates through that day, the working assumption should be compromise:
.env files.claude and .vscode config files in repos for injected persistence---
## HackWire Analysis
ChainDrop is notable not because supply chain attacks are new — they're not — but because of how efficiently this one scaled the propagation graph. The Shai-Hulud lineage has been iterating on NPM worm mechanics for at least two generations now, and the credential-theft-to-republish loop is getting tighter with each variant. The four-hour window from initial compromise to 2,212 malicious versions is an operational tempo that most enterprise security teams simply cannot match.
The injection of Claude and VS Code config files as a persistence vector is worth flagging separately. This reflects something real about how software gets built in 2026: developers trust their editor configs. An organization might have rigorous controls on package installs but nothing watching for changes to .claude/settings.json or .vscode/extensions.json in internal repos. If those configs can push malicious behavior into AI coding assistants or IDE extensions that run with broad file system access, you've found a lateral movement vector that sits entirely outside the traditional threat model.
The EtherHiding C&C escalation is the other piece of technical debt the security ecosystem now owes itself. Blockchain-based C&C was a curiosity when it appeared in adware campaigns. It's now in a sophisticated credential-theft worm targeting production cloud infrastructure. Detection tooling built around C&C domain blocklists and sinkholing has exactly zero efficacy here. Organizations need behavioral detection on outbound traffic patterns and anomalous NPM publish activity — not just another IOC feed.
The practical question organizations should be asking right now isn't "were we hit?" It's "would we know if we were hit 25 hours ago?" If the answer is no, that's the problem to fix.
— HackWire Editorial
---
## Related Coverage