THREATOPS
THREAT OPSThreat News › Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

medelastic_securityPublished 2026-08-06

<p>On August 4, 2026, Elastic Security Labs identified a new Shai-Hulud campaign targeting the maintainer of <code>keyv</code>, a widely used key-value storage library. The attackers trojanized the monorepo and embedded a self-propagating worm called CHAINDROP that uses stolen npm credentials to automatically backdoor every other package the maintainer had publish rights to. The reach of this comp

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain