THREATOPS
THREAT OPSThreat News › Tracking Shai-Hulud: Inside the ChainDrop NPM Worm

Tracking Shai-Hulud: Inside the ChainDrop NPM Worm

medzscaler_threatlabzPublished 2026-08-11

IntroductionOn August 4, 2026, a self-propagating worm called ChainDrop entered the npm ecosystem through a compromised maintainer account. ChainDrop is a variant of Mini Shai-Hulud linked to TeamPCP. ChainDrop anchored its C2 infrastructure in an Ethereum smart contract, allowing the attacker to rotate domains with a single blockchain transaction and rendering domain-based blocklists ineffec

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.zscaler.com/blogs/security-research/tracking-shai-hulud-inside-chaindrop-npm-worm