ChainDrop: the npm Supply-Chain Attack That Compromised 1,300 Packages and Hit 2 Billion Monthly Downloads
The ChainDrop npm supply-chain attack compromised 1,300 packages. Learn how it stole tokens and spread across CI/CD and developer environments.
Illustrative image generated with AI
On August 4, 2026, the ChainDrop campaign was disclosed—a self-propagating supply-chain attack that infected over 1,300 npm packages and reached an estimated 2 billion monthly downloads. The operation, still unfolding, started with the compromise of the Keyv maintainer’s GitHub account and spread downstream through shared dependencies. Researchers from Aikido, Wiz, StepSecurity, Socket, and Ox Security are tracking the expansion and publishing indicators of compromise.
The Trigger: Keyv’s GitHub Account and the Caching Chain
The attacker took control of the GitHub account belonging to the maintainer of Keyv, a widely used key-value store module. From there, malicious code was injected directly into the main branches of Keyv and its dependent packages: Cacheable, flat-cache, and file-entry-cache. To make the new releases appear legitimate, the adversary leveraged the very same GitHub Actions workflows already configured in the repositories. As a result, every infected version published on npm retains a valid provenance attestation, bypassing checks from many supply-chain verification tools.
The Infection Mechanism: preinstall, Bun, and the Obfuscated Payload
Every compromised package includes a setup.mjs file invoked by the preinstall key in package.json. This script runs automatically when someone executes npm install. The dropper downloads the Bun runtime and uses it to execute a second, obfuscated file—Math_Symbol.js (or math_init.js)—which contains an infostealer with self-spreading capabilities.
No user interaction is needed: merely installing an infected dependency triggers the entire chain. Execution takes place on whatever runner performs the install, whether it’s a developer workstation, a CI/CD environment, or a temporary container.
What It Steals and How It Propagates
The infostealer aggressively harvests any credentials accessible from the execution environment:
- GitHub tokens (
ghp_,gho_,ghs_), npm tokens (npm_), and GitHub Actions secrets; - AWS credentials, including values retrieved from SSM with
WithDecryption: trueand secrets from Secrets Manager; - Kubernetes secrets, HashiCorp Vault tokens, database connection strings;
- Stripe, Slack, Twilio, Azure, GCP keys, and the entire process environment.
All stolen data is encrypted and exfiltrated to a public GitHub repository controlled by the attacker. According to Wiz, the domain npm-cache[.]com is also active for exfiltration. The worm doesn’t stop at theft: for every token obtained, it performs a request to registry.npmjs[.]org/-/whoami. If the token is valid, it uses it to infect new packages belonging to the corresponding maintainer. The propagation feeds itself, widening the blast radius with every installation.
Impact: Total Compromise of Development and CI/CD Environments
Any machine that ran npm install on an infected version must be considered fully compromised, even if the package is later removed. The theft of cloud credentials, CI/CD secrets, and private keys opens the door to lateral movement, mass data exfiltration, and unauthorized code changes in repositories of companies like Deliveroo, Ornikar, OneReach, Picsart, Qlik, and ServiceTitan, which have already been impacted by the campaign.
The presence of valid provenance makes the attack particularly insidious: many security tools, relying on attestation-to-source matching, failed to detect anomalies before the first forensic analyses uncovered the mechanism.
How to Defend and Recover
The involved security companies have shared lists of malicious hashes and domains, but the immediate priority for potentially exposed organizations is rapid response:
- Rebuild compromised environments from scratch or restore from clean backups.
- Rotate all tokens and credentials accessible from the impacted environment (GitHub PATs, npm tokens, AWS/GCP/Azure keys, Vault secrets, database and external service credentials).
- Carefully review system logs and repository commits for unusual access or unauthorized modifications.
- Enforce dependency allowlisting and review the execution policies for
preinstallscripts. - Monitor in real time the indicators of compromise shared by Aikido, Wiz, StepSecurity, Socket, and Ox Security.
The ChainDrop campaign is still active, and the number of infected packages continues to rise. Anyone managing npm environments should expect further updates and be prepared to verify the integrity of their dependencies beyond the initial IoC lists.
Sources
This article is an original reworking based on the sources below.




