Malicious self-propagating ChainDrop worm compromises hundreds of npm packages; Keyv/Cacheable hijacked in supply-chain attack using Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2
WizJared WrayAikidoGitHubnpm, Inc.Node Package Manager (npm)

Malicious self-propagating ChainDrop worm compromises hundreds of npm packages; Keyv/Cacheable hijacked in supply-chain attack using Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2

A self-propagating malware known as 'ChainDrop' has compromised over 1,300 npm packages, including popular ones like Keyv and Cacheable, following a supply-chain attack that exploited a GitHub maintainer's account. The worm has affected organizations such as Deliveroo and ServiceTitan, with over 2 billion monthly downloads at risk.

BleepingComputer+2 sources4 August 2026 · 22:11 UTC
CuriousCats Full Story

A self-propagating npm worm called ChainDrop has compromised over 1,300 packages on the Node Package Manager (npm), affecting organizations like Deliveroo and ServiceTitan. The attack began when a GitHub maintainer's account was hijacked, allowing the worm to spread rapidly.13

The worm has been linked to over 2 billion monthly downloads and has infected popular packages such as Keyv and Cacheable. According to Aikido, at least 868 packages across 1,381 versions have been compromised. The attacker pushed malicious files directly to the main branches of these projects, generating new package releases that carried valid provenance information.256

The malicious packages contain two files: the setup.mjs payload dropper and the Math_Symbol.js script for stealing sensitive information. The setup.mjs dropper downloads the Bun JavaScript runtime to execute the infostealer script, which collects developer and cloud credentials and sends them to a public GitHub repository.8

The worm's command-and-control (C2) domains are resolved from an Ethereum smart contract, allowing it to rotate domains at will. This sophisticated attack has expanded its targets for credential theft by nearly 70%, including AI-agent credential stores and cryptocurrency keystores.10

As the attack is ongoing, experts recommend using dependency allowlisting, integrity checks, and provenance controls to mitigate risks.

Key Insight
“ChainDrop spreads by harvesting GitHub tokens, cloud credentials, and CI/CD secrets from infected developer machines and runners, exfiltrating them to npm-cache[.]com, which Wiz flags as a strong indicator of compromise. Aikido counts at least 868 packages across 1,381 versions, including popular caching utilities Keyv, flat-cache, and file-entry-cache.”
CuriousCats studied:
1
BleepingComputer
“Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.”
BleepingComputer →
2
wiz.io
“Multiple npm packages in the `keyv`/`cacheable` ecosystem were compromised following the compromise of a GitHub maintainer account, resulting in the publication of malicious package versions.”
wiz.io →
3
Step Security
“A self-propagating npm worm we call ChainDrop poisoned 444 packages and 2,212 versions in under four hours, starting with keyv@6.0.0.”
Step Security →
Ask CuriousCats
What is the ChainDrop worm?
How does ChainDrop compromise npm packages?
Why is npm-cache[.]com flagged by Wiz?
Are there other supply-chain attacks on npm packages?
How does ChainDrop's approach differ from previous attacks?
Get your CIA-level briefing,
in real time.
CuriousCats monitors the internet every minute for you and brings you the most personalized brief of videos, social media posts, news and more.
Download the App
If you liked this, you’ll love your CuriousCats brief.
News, videos, opinions and more — without the noise.
Get CuriousCats