THREAT OPS › Threat News › Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
<p>On August 4, 2026, Elastic Security Labs identified a new Shai-Hulud campaign targeting the maintainer of <code>keyv</code>, a widely used key-value storage library. The attackers trojanized the monorepo and embedded a self-propagating worm called CHAINDROP that uses stolen npm credentials to automatically backdoor every other package the maintainer had publish rights to. The reach of this comp
MITRE ATT&CK techniques
Indicators of compromise
- 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bccsha256
- fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1ebsha256
- 54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668sha256
- 0xE1f2395ee43e45A1556EC6438a88c31B83493103eth
- npm-cache.comdomain
- go.getblock.iodomain
- eth.llamarpc.comdomain
- eth-mainnet.nodereal.iodomain