Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ChainDrop Attack Infects Over 400 NPM Packages

ChainDrop Attack Infects Over 400 NPM Packages

Posted on August 5, 2026 By CWS

In a significant cybersecurity breach, more than 2,200 malicious versions of 440 packages were uploaded to the NPM registry as part of the latest supply chain attack named ChainDrop. This attack, associated with the Mini Shai-Hulud series, began by compromising 11 packages within the keyv and cacheable namespaces.

Widespread Impact Across the Ecosystem

The infected packages, which collectively receive over 500 million weekly downloads, play a crucial role in the software ecosystem. The contamination extended to 433 additional packages, amplifying the attack’s reach. Similar to earlier Mini Shai-Hulud incidents, the compromised packages executed harmful code upon installation, effectively deploying an information stealer with the capability to propagate itself further.

Once infiltrated, the malware aggressively searches for sensitive data on affected machines. It targets credentials and secrets, encrypting them and sending the data to either dynamic HTTPS endpoints or attacker-operated GitHub repositories labeled ‘Shai-Hulud: Here We Go Again.’

Technical Breakdown and Attack Methodology

According to Microsoft, the malware’s operation involves scanning developer environments, including CI/CD systems, to extract credentials for platforms like NPM, GitHub, AWS, Kubernetes, and HashiCorp Vault. These credentials allow the malware to access and manipulate packages, repositories, and cloud configurations.

The stolen NPM credentials are further utilized to republish tainted versions of packages. Additionally, compromised GitHub credentials enable the malware to alter repositories using GitHub Actions, facilitating further credential theft. JFrog reports that the malware also injects configuration files into repositories to maintain persistence and spread the infection among developers.

Advanced Techniques and Mitigation Strategies

The attack, an evolution of the Shai-Hulud 2.0 worm, employs Ethereum blockchain for command-and-control operations, a method termed EtherHiding. It also implements a dead-man’s switch on macOS and Linux systems, which checks GitHub API responses every minute and self-destructs if the token is invalid.

Developers utilizing the affected packages must consider their systems compromised. It is essential to remove the malware, rebuild CI/CD environments, and rotate credentials. Auditing GitHub repositories for unusual activities is also recommended. JFrog advises isolating impacted systems and preserving logs and package tarballs to assess the extent of the breach.

This incident underscores the importance of robust supply chain security measures for software developers and organizations relying heavily on open-source packages.

Security Week News Tags:ChainDrop, Credentials, Cybersecurity, developer security, GitHub, information stealer, Malware, Mini Shai-Hulud, NPM, supply chain attack

Post navigation

Previous Post: Cybersecurity Evaluation Unveils AI Vulnerabilities
Next Post: 7-Zip Flaw Lets Malicious Files Skirt Windows SmartScreen

Related Posts

Jordanian Admits in US Court to Selling Access to 50 Enterprise Networks Jordanian Admits in US Court to Selling Access to 50 Enterprise Networks Security Week News
Bitwarden NPM Package Compromised in Major Supply Chain Breach Bitwarden NPM Package Compromised in Major Supply Chain Breach Security Week News
US Shuts Down Crypto Exchange E-Note, Charges Russian Administrator US Shuts Down Crypto Exchange E-Note, Charges Russian Administrator Security Week News
AI Vulnerability: ‘HalluSquatting’ Exploits Botnets AI Vulnerability: ‘HalluSquatting’ Exploits Botnets Security Week News
SolarWinds Urges Hotfix for Critical Serv-U Vulnerability SolarWinds Urges Hotfix for Critical Serv-U Vulnerability Security Week News
Chrome, Edge Extensions Caught Tracking Users, Creating Backdoors Chrome, Edge Extensions Caught Tracking Users, Creating Backdoors Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Alerts on Linux Kernel Flaws Under Active Attack
  • TigerByte Cyber Launches with $3M Funding to Enhance Security
  • Identity Visibility: Key to Secure IAM by 2026
  • SolarWinds Fixes Critical ARM Security Flaw
  • Hackers Exploit TanStack to Steal GitHub Repositories

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Alerts on Linux Kernel Flaws Under Active Attack
  • TigerByte Cyber Launches with $3M Funding to Enhance Security
  • Identity Visibility: Key to Secure IAM by 2026
  • SolarWinds Fixes Critical ARM Security Flaw
  • Hackers Exploit TanStack to Steal GitHub Repositories

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark