ON August 4, 2026, Elastic Security Labs reported a resurgence of the Shai-Hulud campaign with the CHAINDROP worm affecting over 400 npm packages. This attack targeted the maintainer of the 'keyv' library, compromising it and embedding a self-propagating worm that uses stolen npm credentials to backdoor associated packages, totaling 1.3 billion monthly downloads.
The worm executes via a 'preinstall' hook in 'package.json' and delivers malicious payloads across multiple platforms, targeting various credential stores, including cloud services and AI tools. The attack includes comprehensive methods for exfiltrating data, querying Ethereum for command and control endpoints, and aggressive credential harvesting. Recommendations for affected users include revoking tokens, adding two-factor authentication, and delaying package updates to prevent compromise.