← Back to Daily Briefing

ChainDrop Worm: Sophisticated npm Supply Chain Attack Leveraging GitHub Actions and Trusted Publishing

Published August 18, 2026

The ChainDrop worm is a self-propagating supply-chain attack that has compromised 444 npm packages, affecting ecosystems with over 2 billion monthly downloads. By compromising high-reputation GitHub accounts, attackers inject malicious code into main branches to trigger automated releases via GitHub Actions. Critically, the use of OpenID Connect (OIDC) through "Trusted Publishing" allows the poisoned packages to arrive with valid provenance and digital signatures, neutralizing traditional integrity checks. The malware employs a multi-stage execution pattern, utilizing the Bun JavaScript runtime to deploy a 710KB obfuscated payload. It utilizes "EtherHiding"—a Command and Control (C2) mechanism leveraging the Ethereum blockchain—to evade network-based detection while targeting cloud credentials, AI-agent configurations, and cryptocurrency keystores.

  • Incident Overview and Scope

    • Compromised 444 unique npm packages and 2,212 specific versions.
    • Impacts critical developer infrastructure with a combined monthly download volume exceeding 2 billion.
    • Represents a 70% increase in credential theft breadth compared to previous Shai-Hulud malware variants.
  • Attack Vector and Execution Mechanics

    • Leverages compromised GitHub maintainer accounts to inject code directly into main branches.
    • Exploits GitHub Actions and OIDC-based "Trusted Publishing" to bypass provenance and integrity checks.
    • Employs an npm preinstall script to fetch the Bun JavaScript runtime.
    • Deploys a 710KB obfuscated secondary payload via setup.mjs, Math_Symbol.js, and math_init.js.
  • Advanced Evasion and C2 Infrastructure

    • Utilizes "EtherHiding" to facilitate Command and Control (C2) via the Ethereum blockchain.
    • Employs blockchain-based communication to evade standard network monitoring and egress filtering.
    • Designed to blend into legitimate decentralized web traffic, complicating signature-based detection.
  • Targeted Data and Persistence Mechanisms

    • Targets cloud provider CLI configurations (AWS, GCP) and CI/CD secrets (Jenkins, Argo CD, Harbor).
    • Targets modern AI-agent credentials (Claude, OpenAI, Gemini, Cursor) and developer IDE settings via VS Code tasks.
    • Attempts persistence through Claude Code hooks and local system files, including /etc/shadow and SSH keys.
    • Actively pursues cryptocurrency keystores including Foundry, Solana, and Monero.
  • Detection and Mitigation Strategies

    • Monitor for unauthorized commits to main branches and unexpected GitHub Action execution triggers.
    • Audit package.json for suspicious preinstall scripts and unauthorized runtime dependencies like Bun.
    • Implement strict branch protection rules and audit OIDC-based publishing permissions.
    • Rotate all cloud, AI-agent, and CI/CD credentials immediately upon detection of suspicious activity.

Related posts

  1. Cybersecurity News — ChainDrop npm Worm Poisons 444 Packages Through GitHub Actions and Trusted Publishing
  2. gbhackers.com — ChainDrop Publishes Initial Malware Without Stealing a Long-Lived npm Token
  3. Malware News — Compromising the Developer: How Modern Dependency Culture Reshaped the Supply Chain Threat Landscape
  4. simplysecuregroup.com — Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
  5. news4hackers.com — North Korean Hackers Exploit Rust Supply Chain: Cybersecurity Threat Revealed
  6. techjacksolutions.com — Megalodon Campaign Poisons 5,500+ GitHub Repos in Six Hours, Developer Credentials and Secrets at Scale
  7. techjacksolutions.com — JINX-0164: macOS Infostealer Campaign Chains Recruiter Lures to npm Supply Chain and CI/CD Compromise
  8. xploitzone.com — Trojanized npm Package Becomes Self Replicating Worm Targeting PyPI Developers Worldwide
  9. forkast.news — The First Supply-Chain Worm Targeting AI Agent Memory Infrastructure Just Hit npm and PyPI
  10. csoonline.com — ChainDrop credential stealing worm infects over 400 npm packages
  11. Ampcuscyber
  12. Sangfor
  13. Falconfeeds
  14. Eon
  15. Stepsecurity
  16. Blog
  17. Suppliershield
  18. Harness
  19. Blog
  20. Scworld
  21. Sygnia
  22. bleepingcomputer.com — Hackers poison arrayref Rust crate to push infostealer malware
  23. thehackernews.com — Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
  24. csoonline.com — Backdoored Rust packages hit crates.io, exposing developers to malware at build time
  25. Infosecurity-magazine
  26. Cryptopolitan
  27. Kucoin
  28. Reconbee
  29. Devops
  30. Research
  31. Stepsecurity
  32. Infoworld
  33. Tuxcare
  34. Darkreading
  35. Labs
  36. Kaseya
  37. Ox
  38. Reddit
  39. Socfortress
  40. Infostealers
  41. Youtube
  42. Safedep
  43. Broadcom
  44. Labs
  45. Facebook
  46. Healsecurity
  47. Infosecurity-magazine
  48. Cybersecuritynews
  49. Blog
  50. Cyberalchemy
  51. Socprime
  52. Endorlabs
  53. Reversinglabs
  54. Expel
  55. Elastic
  56. SecurityWeek — Rust Supply Chain Attack Linked to North Korean Hackers

LINK COPIED TO CLIPBOARD