Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Tracking Shai-Hulud: Inside the ChainDrop NPM Worm

copilot-instructions.md

TLP:CLEAR
Active

Domain

Description

On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and Et...

Sightings (0)

No sightings recorded yet

Details

Name / Label
Tracking Shai-Hulud: Inside the ChainDrop NPM Worm
Pattern Type
STIX
Confidence
75%
Valid From
Aug 12, 2026 12:07
Total Sightings
0
Added
Aug 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of copilot-instructions.md

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.