THREAT OPS › Threat News › Tracking Shai-Hulud: Inside the ChainDrop NPM Worm
Tracking Shai-Hulud: Inside the ChainDrop NPM Worm
IntroductionOn August 4, 2026, a self-propagating worm called ChainDrop entered the npm ecosystem through a compromised maintainer account. ChainDrop is a variant of Mini Shai-Hulud linked to TeamPCP. ChainDrop anchored its C2 infrastructure in an Ethereum smart contract, allowing the attacker to rotate domains with a single blockchain transaction and rendering domain-based blocklists ineffec
MITRE ATT&CK techniques
Indicators of compromise
- 0xE1f2395ee43e45A1556EC6438a88c31B83493103eth
- npm-cache.comdomain