Signal
ChainDrop worm infects over 400 npm packages in massive supply chain attack
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-08-04 16:54 UTCUpdated 2026-08-04 23:46 UTC
rss
cveexploitsmalwaresupply_chain_attackincident_response
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.4 top sources shown
Overview
A large-scale supply chain attack has compromised more than 400 npm packages, including popular ones like keyv and cacheable, affecting over 2 billion monthly downloads combined.
Entities
MicrosoftAlibabakeyvcacheableMini Shai-HuludJared WrayIlyas Makari
Score total
1.49
Momentum 24h
5
Posts
5
Origins
4
Source types
1
Duplicate ratio
0%
Why now
- The attack unfolded rapidly within hours, affecting hundreds of widely used packages.
- Security researchers have just released detailed analyses and mitigation guidance.
- New related threats targeting other developer ecosystems like Alibaba tools have also emerged.
Why it matters
- Highlights critical risks in open-source software supply chains affecting billions of users.
- Demonstrates how malware can self-propagate and steal credentials across multiple cloud and developer platforms.
- Emphasizes the need for improved security practices and detection in software package ecosystems.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
- A self-propagating Mini Shai-Hulud worm infected over 400 npm packages, stealing credentials and spreading rapidly.
- The attack began with the compromise of a GitHub maintainer account for keyv, a package with over 150 million weekly downloads.
- The malware steals credentials from developer workstations and CI/CD environments to access npm, GitHub, AWS, Kubernetes, and HashiCorp Vault.
How sources frame it
- Microsoft Security Research: neutral
All evidence
All evidence
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
Microsoft Security Blog · microsoft.com · 2026-08-04 23:46 UTC
ChainDrop credential stealing worm infects over 400 npm packages
CSO Online · csoonline.com · 2026-08-04 22:37 UTC
Massive supply-chain attack compromises 440 packages under four hours
CyberScoop · cyberscoop.com · 2026-08-04 22:07 UTC
New npm packages deliver remote access trojan targeting Alibaba developers
SC Media · scworld.com · 2026-08-04 20:05 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 4Origin domains: 4Duplicates: -
Showing 4 / 0
Top publishers (this list)
- Microsoft Security Blog (1)
- CSO Online (1)
- CyberScoop (1)
- SC Media (1)
Top origin domains (this list)
- microsoft.com (1)
- csoonline.com (1)
- cyberscoop.com (1)
- scworld.com (1)