Shai-Hulud ChainDrop Worm: Recursive Compromise of npm Ecosystem and keyv/cacheable Libraries
In August 2026, a highly sophisticated self-propagating worm—referred to as both 'Shai-Hulud' and 'ChainDrop'—targeted the npm ecosystem. The attack began by compromising high-traffic caching libraries, such as keyv and cacheable, leveraging 'preinstall' scripts to execute malicious code upon installation. Unlike traditional supply chain attacks, this worm functioned as an infostealer that automatically stole developer credentials to gain publishing rights to other packages. It then autonomously republished malicious updates to those secondary packages, creating a recursive chain of compromise that allowed it to spread rapidly across the software build pipeline, effectively turning the established trust mechanisms of the npm registry into a primary attack surface.