Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ChainDrop Attack Infects Over 400 NPM Packages

ChainDrop Attack Infects Over 400 NPM Packages

Posted on August 5, 2026 By CWS

In a significant cybersecurity breach, more than 2,200 malicious versions of 440 packages were uploaded to the NPM registry as part of the latest supply chain attack named ChainDrop. This attack, associated with the Mini Shai-Hulud series, began by compromising 11 packages within the keyv and cacheable namespaces.

Widespread Impact Across the Ecosystem

The infected packages, which collectively receive over 500 million weekly downloads, play a crucial role in the software ecosystem. The contamination extended to 433 additional packages, amplifying the attack’s reach. Similar to earlier Mini Shai-Hulud incidents, the compromised packages executed harmful code upon installation, effectively deploying an information stealer with the capability to propagate itself further.

Once infiltrated, the malware aggressively searches for sensitive data on affected machines. It targets credentials and secrets, encrypting them and sending the data to either dynamic HTTPS endpoints or attacker-operated GitHub repositories labeled ‘Shai-Hulud: Here We Go Again.’

Technical Breakdown and Attack Methodology

According to Microsoft, the malware’s operation involves scanning developer environments, including CI/CD systems, to extract credentials for platforms like NPM, GitHub, AWS, Kubernetes, and HashiCorp Vault. These credentials allow the malware to access and manipulate packages, repositories, and cloud configurations.

The stolen NPM credentials are further utilized to republish tainted versions of packages. Additionally, compromised GitHub credentials enable the malware to alter repositories using GitHub Actions, facilitating further credential theft. JFrog reports that the malware also injects configuration files into repositories to maintain persistence and spread the infection among developers.

Advanced Techniques and Mitigation Strategies

The attack, an evolution of the Shai-Hulud 2.0 worm, employs Ethereum blockchain for command-and-control operations, a method termed EtherHiding. It also implements a dead-man’s switch on macOS and Linux systems, which checks GitHub API responses every minute and self-destructs if the token is invalid.

Developers utilizing the affected packages must consider their systems compromised. It is essential to remove the malware, rebuild CI/CD environments, and rotate credentials. Auditing GitHub repositories for unusual activities is also recommended. JFrog advises isolating impacted systems and preserving logs and package tarballs to assess the extent of the breach.

This incident underscores the importance of robust supply chain security measures for software developers and organizations relying heavily on open-source packages.

Security Week News Tags:ChainDrop, Credentials, Cybersecurity, developer security, GitHub, information stealer, Malware, Mini Shai-Hulud, NPM, supply chain attack

Post navigation

Previous Post: Cybersecurity Evaluation Unveils AI Vulnerabilities
Next Post: 7-Zip Flaw Lets Malicious Files Skirt Windows SmartScreen

Related Posts

Cityworks Zero-Day Exploited by Chinese Hackers in US Local Government Attacks Cityworks Zero-Day Exploited by Chinese Hackers in US Local Government Attacks Security Week News
Google Warns UK Retailer Hackers Now Targeting US Google Warns UK Retailer Hackers Now Targeting US Security Week News
Iranian Cyber Attackers Deploy Versatile C&C System Iranian Cyber Attackers Deploy Versatile C&C System Security Week News
3 Million Stolen in Cetus Protocol Hack $223 Million Stolen in Cetus Protocol Hack Security Week News
North Korea’s Digital Surge: B Stolen in Crypto as Amazon Blocks 1,800 Fake IT Workers North Korea’s Digital Surge: $2B Stolen in Crypto as Amazon Blocks 1,800 Fake IT Workers Security Week News
Upbound Group Faces  Million Loss from Data Breach Upbound Group Faces $13 Million Loss from Data Breach Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • 7-Zip Flaw Lets Malicious Files Skirt Windows SmartScreen
  • ChainDrop Attack Infects Over 400 NPM Packages
  • Cybersecurity Evaluation Unveils AI Vulnerabilities
  • Botnet Targets Router Diagnostic Tools for Exploitation
  • Cyberattacks on Water Systems Impact Multiple US States

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • 7-Zip Flaw Lets Malicious Files Skirt Windows SmartScreen
  • ChainDrop Attack Infects Over 400 NPM Packages
  • Cybersecurity Evaluation Unveils AI Vulnerabilities
  • Botnet Targets Router Diagnostic Tools for Exploitation
  • Cyberattacks on Water Systems Impact Multiple US States

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark