#worm — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #worm, aggregated by home.social.
-
I had to spend some time on a Windoze 11 machine yesterday. A nasty little worm had managed to take over the Chrome browser. It had removed the Google search engine entry, and when you entered that manually tried to send you to a blacklisted site. It also had taken over the new tab function to do the same.
Fortunately an anti-virus package was blocking the redirect as the site in Blacklisted.
-
I had to spend some time on a Windoze 11 machine yesterday. A nasty little worm had managed to take over the Chrome browser. It had removed the Google search engine entry, and when you entered that manually tried to send you to a blacklisted site. It also had taken over the new tab function to do the same.
Fortunately an anti-virus package was blocking the redirect as the site in Blacklisted.
-
Tracking Shai-Hulud: Inside the ChainDrop NPM Worm
Pulse ID: 6a7d499c37a8eebd3c318b8a
Pulse Link: https://otx.alienvault.com/pulse/6a7d499c37a8eebd3c318b8a
Pulse Author: Tr1sa111
Created: 2026-08-13 04:35:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #Worm #bot #Tr1sa111
-
Tracking Shai-Hulud: Inside the ChainDrop NPM Worm
Pulse ID: 6a7d499c37a8eebd3c318b8a
Pulse Link: https://otx.alienvault.com/pulse/6a7d499c37a8eebd3c318b8a
Pulse Author: Tr1sa111
Created: 2026-08-13 04:35:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #Worm #bot #Tr1sa111
-
Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals
Indicators extracted from public reporting. Source: https://cert.gov.ua/article/6318863
Pulse ID: 6a7c433680aefab88821c968
Pulse Link: https://otx.alienvault.com/pulse/6a7c433680aefab88821c968
Pulse Author: CyberHunter_NL
Created: 2026-08-12 09:56:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL
-
Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals
Indicators extracted from public reporting. Source: https://cert.gov.ua/article/6318863
Pulse ID: 6a7c433680aefab88821c968
Pulse Link: https://otx.alienvault.com/pulse/6a7c433680aefab88821c968
Pulse Author: CyberHunter_NL
Created: 2026-08-12 09:56:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL
-
Tracking Shai-Hulud: Inside the ChainDrop NPM Worm
On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.
Pulse ID: 6a7bdb4167c384aad06f1253
Pulse Link: https://otx.alienvault.com/pulse/6a7bdb4167c384aad06f1253
Pulse Author: AlienVault
Created: 2026-08-12 02:32:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #CyberSecurity #ELF #EtherHiding #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Worm #bot #AlienVault
-
Tracking Shai-Hulud: Inside the ChainDrop NPM Worm
On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.
Pulse ID: 6a7bdb4167c384aad06f1253
Pulse Link: https://otx.alienvault.com/pulse/6a7bdb4167c384aad06f1253
Pulse Author: AlienVault
Created: 2026-08-12 02:32:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #CyberSecurity #ELF #EtherHiding #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Worm #bot #AlienVault
-
Watch for Invasive Jumping Worms in Your Minnesota Garden https://www.allforgardening.com/1928074/watch-for-invasive-jumping-worms-in-your-minnesota-garden/ #earthworm #garden #gardening #GardeningMinnesota #JumpingWorm #minnesota #MNDNR #outdoors #StCloudNews #Worm
-
Watch for Invasive Jumping Worms in Your Minnesota Garden https://www.allforgardening.com/1928074/watch-for-invasive-jumping-worms-in-your-minnesota-garden/ #earthworm #garden #gardening #GardeningMinnesota #JumpingWorm #minnesota #MNDNR #outdoors #StCloudNews #Worm
-
Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack
Pulse ID: 6a7bf84d462efb3893c6dd40
Pulse Link: https://otx.alienvault.com/pulse/6a7bf84d462efb3893c6dd40
Pulse Author: Tr1sa111
Created: 2026-08-12 04:36:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #Worm #bot #Tr1sa111
-
Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack
Pulse ID: 6a7bf84d462efb3893c6dd40
Pulse Link: https://otx.alienvault.com/pulse/6a7bf84d462efb3893c6dd40
Pulse Author: Tr1sa111
Created: 2026-08-12 04:36:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #Worm #bot #Tr1sa111
-
Sandworm hackers target IT pros with trojanized WireGuard VPN client
Indicators extracted from public reporting. Source: https://cert.gov.ua/article/6318863
Pulse ID: 6a7b9a56ed0787edeab00dfb
Pulse Link: https://otx.alienvault.com/pulse/6a7b9a56ed0787edeab00dfb
Pulse Author: CyberHunter_NL
Created: 2026-08-11 21:55:34Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL
-
Sandworm hackers target IT pros with trojanized WireGuard VPN client
Indicators extracted from public reporting. Source: https://cert.gov.ua/article/6318863
Pulse ID: 6a7b9a56ed0787edeab00dfb
Pulse Link: https://otx.alienvault.com/pulse/6a7b9a56ed0787edeab00dfb
Pulse Author: CyberHunter_NL
Created: 2026-08-11 21:55:34Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL
-
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
Indicators extracted from public reporting. Source: https://cert.gov.ua/article/6318863
Pulse ID: 6a7b70b8ec4054a06540defa
Pulse Link: https://otx.alienvault.com/pulse/6a7b70b8ec4054a06540defa
Pulse Author: CyberHunter_NL
Created: 2026-08-11 18:58:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #VPN #Worm #bot #CyberHunter_NL
-
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
Indicators extracted from public reporting. Source: https://cert.gov.ua/article/6318863
Pulse ID: 6a7b70b8ec4054a06540defa
Pulse Link: https://otx.alienvault.com/pulse/6a7b70b8ec4054a06540defa
Pulse Author: CyberHunter_NL
Created: 2026-08-11 18:58:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #VPN #Worm #bot #CyberHunter_NL
-
Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack
A large-scale software supply chain attack compromised over 400 npm packages through a self-propagating worm called ChainDrop, a new variant of Mini Shai-Hulud. The campaign exploits stolen npm publishing credentials to automatically modify and republish legitimate software releases. ChainDrop targets developer workstations and CI/CD environments, harvesting credentials from npm, GitHub, AWS, Kubernetes, and HashiCorp Vault before validating access and enumerating resources. The malware uses preinstall lifecycle scripts for automatic execution, establishes persistence through repository configuration modifications, and abuses GitHub Actions OIDC trusted publishing workflows. After stealing credentials, it autonomously propagates by downloading packages, inserting malicious payloads, and republishing them with incremented versions, demonstrating how compromised developer identities can enable widespread ecosystem compromise.
Pulse ID: 6a7b39b0e4765559a182c347
Pulse Link: https://otx.alienvault.com/pulse/6a7b39b0e4765559a182c347
Pulse Author: AlienVault
Created: 2026-08-11 15:03:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #RCE #Rust #SupplyChain #Worm #bot #AlienVault
-
Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack
A large-scale software supply chain attack compromised over 400 npm packages through a self-propagating worm called ChainDrop, a new variant of Mini Shai-Hulud. The campaign exploits stolen npm publishing credentials to automatically modify and republish legitimate software releases. ChainDrop targets developer workstations and CI/CD environments, harvesting credentials from npm, GitHub, AWS, Kubernetes, and HashiCorp Vault before validating access and enumerating resources. The malware uses preinstall lifecycle scripts for automatic execution, establishes persistence through repository configuration modifications, and abuses GitHub Actions OIDC trusted publishing workflows. After stealing credentials, it autonomously propagates by downloading packages, inserting malicious payloads, and republishing them with incremented versions, demonstrating how compromised developer identities can enable widespread ecosystem compromise.
Pulse ID: 6a7b39b0e4765559a182c347
Pulse Link: https://otx.alienvault.com/pulse/6a7b39b0e4765559a182c347
Pulse Author: AlienVault
Created: 2026-08-11 15:03:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #RCE #Rust #SupplyChain #Worm #bot #AlienVault
-
The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications
Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.
Pulse ID: 6a7a8be76fe0dfa36d01afa0
Pulse Link: https://otx.alienvault.com/pulse/6a7a8be76fe0dfa36d01afa0
Pulse Author: AlienVault
Created: 2026-08-11 02:41:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #CyberSecurity #ELF #Encryption #Endpoint #InfoSec #LawEnforcement #Mac #Malware #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RCE #RPC #Telegram #Word #Worm #XWorm #bot #botnet #cryptocurrency #AlienVault
-
The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications
Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.
Pulse ID: 6a7a8be76fe0dfa36d01afa0
Pulse Link: https://otx.alienvault.com/pulse/6a7a8be76fe0dfa36d01afa0
Pulse Author: AlienVault
Created: 2026-08-11 02:41:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #CyberSecurity #ELF #Encryption #Endpoint #InfoSec #LawEnforcement #Mac #Malware #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RCE #RPC #Telegram #Word #Worm #XWorm #bot #botnet #cryptocurrency #AlienVault
-
Inside a Self-Propagating npm Worm
Pulse ID: 6a7951d7e4e9679263bf13be
Pulse Link: https://otx.alienvault.com/pulse/6a7951d7e4e9679263bf13be
Pulse Author: Tr1sa111
Created: 2026-08-10 04:21:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #Worm #bot #Tr1sa111
-
Inside a Self-Propagating npm Worm
Pulse ID: 6a7951d7e4e9679263bf13be
Pulse Link: https://otx.alienvault.com/pulse/6a7951d7e4e9679263bf13be
Pulse Author: Tr1sa111
Created: 2026-08-10 04:21:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #Worm #bot #Tr1sa111
-
@theprimetimeagen on YT! 📺
"10% of the world computers were hacked"
https://youtu.be/xNcrfveKlDU?si=zFPYt9xs8ue9KR-W
#Worm #YCombinator #computerhistory
( Ed : stop this madness 😬)
8/9/2026
-
@theprimetimeagen on YT! 📺
"10% of the world computers were hacked"
https://youtu.be/xNcrfveKlDU?si=zFPYt9xs8ue9KR-W
#Worm #YCombinator #computerhistory
( Ed : stop this madness 😬)
8/9/2026
-
ChainDrop npm Supply Chain Worm Attack Target Developers and CI/CD Environments
Pulse ID: 6a76817228e67b24b4fb3e61
Pulse Link: https://otx.alienvault.com/pulse/6a76817228e67b24b4fb3e61
Pulse Author: cryptocti
Created: 2026-08-08 01:08:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #Worm #bot #developers #cryptocti
-
ChainDrop npm Supply Chain Worm Attack Target Developers and CI/CD Environments
Pulse ID: 6a76817228e67b24b4fb3e61
Pulse Link: https://otx.alienvault.com/pulse/6a76817228e67b24b4fb3e61
Pulse Author: cryptocti
Created: 2026-08-08 01:08:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #Worm #bot #developers #cryptocti
-
This Week in Security: Claude Gets Hacking, Hotel WiFi, and NPM Compromised Again
-
ChainDrop Worm Infects 400+ npm Packages to Steal GitHub and Cloud Credentials
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/
Pulse ID: 6a75c82b4f039349fc0ef35d
Pulse Link: https://otx.alienvault.com/pulse/6a75c82b4f039349fc0ef35d
Pulse Author: CyberHunter_NL
Created: 2026-08-07 11:57:31Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #NPM #OTX #OpenThreatExchange #RCE #Worm #bot #CyberHunter_NL
-
ChainDrop Worm Infects 400+ npm Packages to Steal GitHub and Cloud Credentials
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/
Pulse ID: 6a75c82b4f039349fc0ef35d
Pulse Link: https://otx.alienvault.com/pulse/6a75c82b4f039349fc0ef35d
Pulse Author: CyberHunter_NL
Created: 2026-08-07 11:57:31Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #NPM #OTX #OpenThreatExchange #RCE #Worm #bot #CyberHunter_NL
-
Inside a Self-Propagating npm Worm
A self-propagating npm worm dubbed ChainDrop infected over 400 packages downloaded hundreds of millions of times weekly, including popular packages like keyv and cacheable-request. The worm steals cloud credentials, npm and GitHub tokens, SSH keys, and sensitive developer data while extracting temporary credentials from GitHub Actions runner memory. It uses stolen npm publishing tokens to infect additional packages while maintaining their legitimate functionality. The attackers established persistence through VS Code and Claude Code configurations, employed blockchain-based command-and-control resolution via Ethereum smart contracts, and can execute attacker-supplied code. The operator demonstrated ability to silently reconfigure C2 infrastructure through Ethereum transactions without updating deployed instances. ChainDrop employs three layers of obfuscation and encryption, exfiltrates data through encrypted channels, and publishes stolen tokens in public commit messages.
Pulse ID: 6a75b2f415506d0a2374398b
Pulse Link: https://otx.alienvault.com/pulse/6a75b2f415506d0a2374398b
Pulse Author: AlienVault
Created: 2026-08-07 10:27:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Cloud #CyberSecurity #ELF #Encryption #GitHub #InfoSec #NPM #OTX #OpenThreatExchange #RAT #SSH #Worm #bot #AlienVault
-
Inside a Self-Propagating npm Worm
A self-propagating npm worm dubbed ChainDrop infected over 400 packages downloaded hundreds of millions of times weekly, including popular packages like keyv and cacheable-request. The worm steals cloud credentials, npm and GitHub tokens, SSH keys, and sensitive developer data while extracting temporary credentials from GitHub Actions runner memory. It uses stolen npm publishing tokens to infect additional packages while maintaining their legitimate functionality. The attackers established persistence through VS Code and Claude Code configurations, employed blockchain-based command-and-control resolution via Ethereum smart contracts, and can execute attacker-supplied code. The operator demonstrated ability to silently reconfigure C2 infrastructure through Ethereum transactions without updating deployed instances. ChainDrop employs three layers of obfuscation and encryption, exfiltrates data through encrypted channels, and publishes stolen tokens in public commit messages.
Pulse ID: 6a75b2f415506d0a2374398b
Pulse Link: https://otx.alienvault.com/pulse/6a75b2f415506d0a2374398b
Pulse Author: AlienVault
Created: 2026-08-07 10:27:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Cloud #CyberSecurity #ELF #Encryption #GitHub #InfoSec #NPM #OTX #OpenThreatExchange #RAT #SSH #Worm #bot #AlienVault
-
Shai-Hulud CHAINDROP Worm Backdoors 400+ npm Packages With 1.3 Billion Monthly Downloads
Indicators extracted from public reporting. Source: https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain
Pulse ID: 6a7591439f7119bc3233bc3d
Pulse Link: https://otx.alienvault.com/pulse/6a7591439f7119bc3233bc3d
Pulse Author: CyberHunter_NL
Created: 2026-08-07 08:03:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #NPM #OTX #OpenThreatExchange #RCE #Worm #bot #CyberHunter_NL
-
Shai-Hulud CHAINDROP Worm Backdoors 400+ npm Packages With 1.3 Billion Monthly Downloads
Indicators extracted from public reporting. Source: https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain
Pulse ID: 6a7591439f7119bc3233bc3d
Pulse Link: https://otx.alienvault.com/pulse/6a7591439f7119bc3233bc3d
Pulse Author: CyberHunter_NL
Created: 2026-08-07 08:03:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #NPM #OTX #OpenThreatExchange #RCE #Worm #bot #CyberHunter_NL
-
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
Pulse ID: 6a75637274868daf87b73448
Pulse Link: https://otx.alienvault.com/pulse/6a75637274868daf87b73448
Pulse Author: Tr1sa111
Created: 2026-08-07 04:47:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #Worm #bot #Tr1sa111
-
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
Pulse ID: 6a75637274868daf87b73448
Pulse Link: https://otx.alienvault.com/pulse/6a75637274868daf87b73448
Pulse Author: Tr1sa111
Created: 2026-08-07 04:47:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #Worm #bot #Tr1sa111
-
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
Pulse ID: 6a7563c638c9a3ca0209c73b
Pulse Link: https://otx.alienvault.com/pulse/6a7563c638c9a3ca0209c73b
Pulse Author: Tr1sa111
Created: 2026-08-07 04:49:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #Worm #bot #Tr1sa111
-
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
Pulse ID: 6a7563c638c9a3ca0209c73b
Pulse Link: https://otx.alienvault.com/pulse/6a7563c638c9a3ca0209c73b
Pulse Author: Tr1sa111
Created: 2026-08-07 04:49:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #Worm #bot #Tr1sa111
-
ChainDrop: Inside a Self-Propagating npm Worm
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/
Pulse ID: 6a751f2c22e68481012c2e2d
Pulse Link: https://otx.alienvault.com/pulse/6a751f2c22e68481012c2e2d
Pulse Author: CyberHunter_NL
Created: 2026-08-06 23:56:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ELF #HTTP #HTTPS #InfoSec #NPM #OTX #OpenThreatExchange #RCE #Worm #bot #CyberHunter_NL
-
ChainDrop: Inside a Self-Propagating npm Worm
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/
Pulse ID: 6a751f2c22e68481012c2e2d
Pulse Link: https://otx.alienvault.com/pulse/6a751f2c22e68481012c2e2d
Pulse Author: CyberHunter_NL
Created: 2026-08-06 23:56:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ELF #HTTP #HTTPS #InfoSec #NPM #OTX #OpenThreatExchange #RCE #Worm #bot #CyberHunter_NL
-
ChainDrop npm Attack Compromises Hundreds of Packages
A sophisticated software supply chain attack named ChainDrop has infected hundreds of npm packages, including popular caching libraries with millions of weekly downloads. Beginning August 4, 2026, attackers compromised a GitHub account of a keyv package maintainer, injecting malicious code into legitimate repositories. The malware executes credential-stealing payloads targeting developer workstations and CI/CD runners, harvesting npm tokens, GitHub credentials, cloud access keys, SSH keys, and database credentials. Using stolen credentials, the worm self-propagates by compromising additional repositories and publishing poisoned packages with valid provenance attestations. ChainDrop employs Bun runtime for execution, establishes persistence through developer tool configurations, and exfiltrates encrypted data using blockchain-based command-and-control infrastructure. This campaign represents an evolution of the Shai-Hulud npm worm.
Pulse ID: 6a7484b807f5882281629fae
Pulse Link: https://otx.alienvault.com/pulse/6a7484b807f5882281629fae
Pulse Author: AlienVault
Created: 2026-08-06 12:57:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SSH #SupplyChain #Worm #bot #AlienVault
-
ChainDrop npm Attack Compromises Hundreds of Packages
A sophisticated software supply chain attack named ChainDrop has infected hundreds of npm packages, including popular caching libraries with millions of weekly downloads. Beginning August 4, 2026, attackers compromised a GitHub account of a keyv package maintainer, injecting malicious code into legitimate repositories. The malware executes credential-stealing payloads targeting developer workstations and CI/CD runners, harvesting npm tokens, GitHub credentials, cloud access keys, SSH keys, and database credentials. Using stolen credentials, the worm self-propagates by compromising additional repositories and publishing poisoned packages with valid provenance attestations. ChainDrop employs Bun runtime for execution, establishes persistence through developer tool configurations, and exfiltrates encrypted data using blockchain-based command-and-control infrastructure. This campaign represents an evolution of the Shai-Hulud npm worm.
Pulse ID: 6a7484b807f5882281629fae
Pulse Link: https://otx.alienvault.com/pulse/6a7484b807f5882281629fae
Pulse Author: AlienVault
Created: 2026-08-06 12:57:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SSH #SupplyChain #Worm #bot #AlienVault
-
Major Shai Hulud campaign strikes npm again, affecting keyv and 400+ packages
A sophisticated supply-chain attack campaign named Shai-Hulud has compromised over 400 npm packages across 1700+ versions, beginning with keyv and cacheable libraries. The malware operates as a self-propagating worm that collects credentials from local filesystems, CI/CD environments, cloud platforms, Kubernetes clusters, and HashiCorp Vault. It exfiltrates stolen data through dynamic HTTPS endpoints or public GitHub repositories, then uses compromised npm tokens to publish infected versions of all writable packages. The campaign also injects execution hooks into GitHub repositories via VS Code and Claude configuration files, harvests GitHub Actions secrets through injected workflows, and includes a targeted attack against npm trusted publishing flows. Command and control infrastructure leverages Ethereum smart contracts and GitHub commit messages for resilience.
Pulse ID: 6a74570cf5cc7a08cd8e9903
Pulse Link: https://otx.alienvault.com/pulse/6a74570cf5cc7a08cd8e9903
Pulse Author: AlienVault
Created: 2026-08-06 09:42:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #ELF #Endpoint #GitHub #HTTP #HTTPS #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Rust #Worm #bot #AlienVault
-
Major Shai Hulud campaign strikes npm again, affecting keyv and 400+ packages
A sophisticated supply-chain attack campaign named Shai-Hulud has compromised over 400 npm packages across 1700+ versions, beginning with keyv and cacheable libraries. The malware operates as a self-propagating worm that collects credentials from local filesystems, CI/CD environments, cloud platforms, Kubernetes clusters, and HashiCorp Vault. It exfiltrates stolen data through dynamic HTTPS endpoints or public GitHub repositories, then uses compromised npm tokens to publish infected versions of all writable packages. The campaign also injects execution hooks into GitHub repositories via VS Code and Claude configuration files, harvests GitHub Actions secrets through injected workflows, and includes a targeted attack against npm trusted publishing flows. Command and control infrastructure leverages Ethereum smart contracts and GitHub commit messages for resilience.
Pulse ID: 6a74570cf5cc7a08cd8e9903
Pulse Link: https://otx.alienvault.com/pulse/6a74570cf5cc7a08cd8e9903
Pulse Author: AlienVault
Created: 2026-08-06 09:42:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #ELF #Endpoint #GitHub #HTTP #HTTPS #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Rust #Worm #bot #AlienVault
-
Supply Chain Compromise Affecting keyv and cacheable npm Packages
An active supply chain attack has compromised the keyv and cacheable npm packages, affecting tens of millions of weekly downloads. The attack began on August 4, 2026, when the maintainer account Jaredwray was compromised, enabling attackers to publish malicious code across multiple packages. The malware deploys through a preinstall hook that downloads a Bun runtime and executes obfuscated payloads designed to harvest cloud credentials from AWS, GCP, Azure, HashiCorp Vault, Kubernetes, GitHub Actions, and npm tokens. The threat exhibits worm-like behavior by using stolen npm tokens to republish trojanized versions of additional packages beyond the original namespaces. Stolen credentials are exfiltrated to attacker-controlled GitHub repositories via DNS-resolved destinations, with persistence mechanisms planted in developer environments through .claude and .vscode hooks.
Pulse ID: 6a744e3869101e8bea80db85
Pulse Link: https://otx.alienvault.com/pulse/6a744e3869101e8bea80db85
Pulse Author: AlienVault
Created: 2026-08-06 09:04:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #Cloud #CyberSecurity #DNS #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SMS #SupplyChain #Trojan #Troll #Worm #bot #AlienVault
-
Supply Chain Compromise Affecting keyv and cacheable npm Packages
An active supply chain attack has compromised the keyv and cacheable npm packages, affecting tens of millions of weekly downloads. The attack began on August 4, 2026, when the maintainer account Jaredwray was compromised, enabling attackers to publish malicious code across multiple packages. The malware deploys through a preinstall hook that downloads a Bun runtime and executes obfuscated payloads designed to harvest cloud credentials from AWS, GCP, Azure, HashiCorp Vault, Kubernetes, GitHub Actions, and npm tokens. The threat exhibits worm-like behavior by using stolen npm tokens to republish trojanized versions of additional packages beyond the original namespaces. Stolen credentials are exfiltrated to attacker-controlled GitHub repositories via DNS-resolved destinations, with persistence mechanisms planted in developer environments through .claude and .vscode hooks.
Pulse ID: 6a744e3869101e8bea80db85
Pulse Link: https://otx.alienvault.com/pulse/6a744e3869101e8bea80db85
Pulse Author: AlienVault
Created: 2026-08-06 09:04:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #Cloud #CyberSecurity #DNS #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SMS #SupplyChain #Trojan #Troll #Worm #bot #AlienVault
-
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
On August 4, 2026, a sophisticated supply chain attack compromised the keyv npm package maintainer, deploying CHAINDROP, a self-propagating worm that automatically backdoors packages using stolen npm credentials. Over 400 npm packages were infected, affecting more than 1.3 billion monthly downloads. The worm executes via preinstall hooks, deploys across Linux, macOS, and Windows platforms, and harvests credentials from over 300 patterns targeting AI tooling, cloud providers, GitHub tokens, and npm credentials. CHAINDROP uses Ethereum smart contracts for C2 resolution and propagates by publishing trojanized versions of packages the compromised maintainer can access. The payload is heavily obfuscated and contains Dune-themed references consistent with previous Shai-Hulud campaigns.
Pulse ID: 6a73cac4902afff959b758aa
Pulse Link: https://otx.alienvault.com/pulse/6a73cac4902afff959b758aa
Pulse Author: AlienVault
Created: 2026-08-05 23:44:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Linux #Mac #MacOS #NPM #OTX #OpenThreatExchange #SupplyChain #Trojan #Windows #Worm #bot #AlienVault
-
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
On August 4, 2026, a sophisticated supply chain attack compromised the keyv npm package maintainer, deploying CHAINDROP, a self-propagating worm that automatically backdoors packages using stolen npm credentials. Over 400 npm packages were infected, affecting more than 1.3 billion monthly downloads. The worm executes via preinstall hooks, deploys across Linux, macOS, and Windows platforms, and harvests credentials from over 300 patterns targeting AI tooling, cloud providers, GitHub tokens, and npm credentials. CHAINDROP uses Ethereum smart contracts for C2 resolution and propagates by publishing trojanized versions of packages the compromised maintainer can access. The payload is heavily obfuscated and contains Dune-themed references consistent with previous Shai-Hulud campaigns.
Pulse ID: 6a73cac4902afff959b758aa
Pulse Link: https://otx.alienvault.com/pulse/6a73cac4902afff959b758aa
Pulse Author: AlienVault
Created: 2026-08-05 23:44:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Linux #Mac #MacOS #NPM #OTX #OpenThreatExchange #SupplyChain #Trojan #Windows #Worm #bot #AlienVault
-
ChainDrop: The Mini Shai Hulud npm worm's latest wave hits keyv and cacheable
Pulse ID: 6a740df2b6c618fb0fced9ae
Pulse Link: https://otx.alienvault.com/pulse/6a740df2b6c618fb0fced9ae
Pulse Author: Tr1sa111
Created: 2026-08-06 04:30:42Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #Worm #bot #Tr1sa111
-
ChainDrop: The Mini Shai Hulud npm worm's latest wave hits keyv and cacheable
Pulse ID: 6a740df2b6c618fb0fced9ae
Pulse Link: https://otx.alienvault.com/pulse/6a740df2b6c618fb0fced9ae
Pulse Author: Tr1sa111
Created: 2026-08-06 04:30:42Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #Worm #bot #Tr1sa111
-
ChainDrop: The Mini Shai Hulud npm worm's latest wave hits keyv and cacheable
Attackers compromised a GitHub maintainer account controlling keyv, cacheable, flat-cache, and file-entry-cache Node.js packages that collectively receive over a billion downloads monthly. Malicious code was pushed directly to the main branch and automatically published to npm with valid signatures. A hidden preinstall script downloads a Bun runtime to execute an obfuscated payload that harvests npm, GitHub, AWS, Kubernetes, and Vault credentials, scans for SSH keys and environment files, and exfiltrates data to attacker-controlled GitHub repositories and Ethereum smart contracts. The worm then uses stolen npm tokens to infect additional packages autonomously. This self-propagating attack, tracked as ChainDrop, belongs to the Shai Hulud family responsible for previous campaigns targeting TanStack, Mistral AI, and OpenSearch packages in May 2026.
Pulse ID: 6a72f4367f010bc9d645f5d1
Pulse Link: https://otx.alienvault.com/pulse/6a72f4367f010bc9d645f5d1
Pulse Author: AlienVault
Created: 2026-08-05 08:28:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #CyberSecurity #ELF #GitHub #InfoSec #NPM #Nodejs #OTX #OpenThreatExchange #RAT #SSH #Troll #Worm #bot #AlienVault
-
ChainDrop: The Mini Shai Hulud npm worm's latest wave hits keyv and cacheable
Attackers compromised a GitHub maintainer account controlling keyv, cacheable, flat-cache, and file-entry-cache Node.js packages that collectively receive over a billion downloads monthly. Malicious code was pushed directly to the main branch and automatically published to npm with valid signatures. A hidden preinstall script downloads a Bun runtime to execute an obfuscated payload that harvests npm, GitHub, AWS, Kubernetes, and Vault credentials, scans for SSH keys and environment files, and exfiltrates data to attacker-controlled GitHub repositories and Ethereum smart contracts. The worm then uses stolen npm tokens to infect additional packages autonomously. This self-propagating attack, tracked as ChainDrop, belongs to the Shai Hulud family responsible for previous campaigns targeting TanStack, Mistral AI, and OpenSearch packages in May 2026.
Pulse ID: 6a72f4367f010bc9d645f5d1
Pulse Link: https://otx.alienvault.com/pulse/6a72f4367f010bc9d645f5d1
Pulse Author: AlienVault
Created: 2026-08-05 08:28:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #CyberSecurity #ELF #GitHub #InfoSec #NPM #Nodejs #OTX #OpenThreatExchange #RAT #SSH #Troll #Worm #bot #AlienVault
-
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
Indicators extracted from public reporting. Source: https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/
Pulse ID: 6a729920ce4597d7b978f0b1
Pulse Link: https://otx.alienvault.com/pulse/6a729920ce4597d7b978f0b1
Pulse Author: CyberHunter_NL
Created: 2026-08-05 02:00:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ELF #HTTP #HTTPS #InfoSec #Microsoft #NATO #OTX #OpenThreatExchange #RCE #SupplyChain #Worm #bot #CyberHunter_NL
-
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
Indicators extracted from public reporting. Source: https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/
Pulse ID: 6a729920ce4597d7b978f0b1
Pulse Link: https://otx.alienvault.com/pulse/6a729920ce4597d7b978f0b1
Pulse Author: CyberHunter_NL
Created: 2026-08-05 02:00:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ELF #HTTP #HTTPS #InfoSec #Microsoft #NATO #OTX #OpenThreatExchange #RCE #SupplyChain #Worm #bot #CyberHunter_NL
-
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html?m=1