www.elastic.co 8/5/2026, 10:11:25 PM · external

CHAINDROP worm hijacks npm’s keyv, threatens 1.3bn downloads

CHAINDROP worm hijacks npm’s keyv, threatens 1.3bn downloads
CyberSIXT Evidence Panel Source marked as original reporting

ON August 4, 2026, Elastic Security Labs reported a resurgence of the Shai-Hulud campaign with the CHAINDROP worm affecting over 400 npm packages. This attack targeted the maintainer of the 'keyv' library, compromising it and embedding a self-propagating worm that uses stolen npm credentials to backdoor associated packages, totaling 1.3 billion monthly downloads.

The worm executes via a 'preinstall' hook in 'package.json' and delivers malicious payloads across multiple platforms, targeting various credential stores, including cloud services and AI tools. The attack includes comprehensive methods for exfiltrating data, querying Ethereum for command and control endpoints, and aggressive credential harvesting. Recommendations for affected users include revoking tokens, adding two-factor authentication, and delaying package updates to prevent compromise.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline