ChainDrop is a self-propagating NPM worm that entered the npm ecosystem on August 4, 2026 through a compromised maintainer account of the keyv ecosystem. The attacker pushed malicious commits to source repositories, causing trusted GitHub Actions release pipelines to build and publish poisoned packages with valid SLSA Build Level 3 provenance. The worm spread to over 400 packages by stealing npm tokens and republishing infected versions, using Bun runtime to evade Node.js-focused security tools and anchoring C2 infrastructure in an Ethereum smart contract for resilient domain rotation.
npm-worm
1 post
ChainDrop NPM Worm Analysis | ThreatLabz