{"id":6539,"date":"2026-08-15T16:20:32","date_gmt":"2026-08-15T16:20:32","guid":{"rendered":"https:\/\/areeblog.com\/?p=6539"},"modified":"2026-08-15T16:20:32","modified_gmt":"2026-08-15T16:20:32","slug":"chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack","status":"publish","type":"post","link":"https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/","title":{"rendered":"ChainDrop Hits 444 npm Packages in New Self-Propagating Supply-Chain Attack"},"content":{"rendered":"<p><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"6540\" data-permalink=\"https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/images-33\/\" data-orig-file=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-33.jpeg\" data-orig-size=\"739,415\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;,&quot;alt&quot;:&quot;&quot;}\" data-image-title=\"images (33)\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-33.jpeg\" class=\"aligncenter size-full wp-image-6540\" src=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-33.jpeg\" alt=\"ChainDrop Hits 444 npm Packages in New Self-Propagating Supply-Chain Attack\" width=\"739\" height=\"415\" srcset=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-33.jpeg 739w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-33-300x168.jpeg 300w\" sizes=\"auto, (max-width: 739px) 100vw, 739px\" \/><\/p>\n<p>A new npm supply-chain attack has compromised hundreds of JavaScript packages and turned <a href=\"https:\/\/areeblog.com\/one-billion-salesforce-records-reportedly-stolen\/\">stolen developer credentials<\/a> into a mechanism for spreading the malware to additional projects. Researchers tracking the campaign have identified 444 unique npm packages and 2,212 compromised versions in one August 4 investigation snapshot, while separate researchers recorded different totals as the campaign evolved.<\/p>\n<p>The incident, dubbed ChainDrop, has been analyzed independently by security researchers including StepSecurity, Microsoft and Palo Alto Networks.<\/p>\n<p>Their investigations show a campaign designed not only to execute malicious code when affected packages are installed, but also to collect credentials from developer systems and continuous integration and continuous delivery environments, use those credentials to access additional packages and repositories, and continue propagating.<\/p>\n<p>The scale figures require careful attribution. StepSecurity&#8217;s detailed August 4 forensic analysis counted 444 unique packages and 2,212 compromised versions during a period of roughly 09:40 to 13:20 UTC.<\/p>\n<p>Other investigations produced different counts based on later or different snapshots, so the figures should not be combined into a single campaign total. <a href=\"https:\/\/www.stepsecurity.io\/blog\/chaindrop-npm-worm\">StepSecurity&#8217;s technical analysis<\/a> provides the detailed package and version breakdown.<\/p>\n<ul>\n<li>StepSecurity identified 444 unique packages and 2,212 compromised versions in its August 4 snapshot.<\/li>\n<li>Microsoft independently described the campaign as a self-propagating worm affecting more than 400 npm packages.<\/li>\n<li>The first confirmed malicious release identified by StepSecurity was <code>keyv@6.0.0<\/code>.<\/li>\n<li>The malware uses npm installation hooks, stolen credentials and automated package publishing to spread.<\/li>\n<li>Researchers found collection mechanisms for npm, GitHub, cloud, Kubernetes, Vault and several AI development environments.<\/li>\n<\/ul>\n<p>StepSecurity identified <code>keyv@6.0.0<\/code> as the first confirmed malicious release in the campaign, published at about 09:35 UTC on August 4. The package has a large download base, and the researchers also identified malicious releases of packages including <code>flat-cache@6.1.24<\/code> and <code>file-entry-cache@11.1.6<\/code>.<\/p>\n<p>The initial set identified by StepSecurity contained 11 packages that acted as the first worm carriers. They included packages in the Keyv and Cacheable ecosystems such as <code>cacheable-request@13.0.20<\/code>, <code>@cacheable\/utils@2.5.1<\/code>, <code>cacheable@2.5.1<\/code>, <code>@cacheable\/memory@2.2.1<\/code>, <code>cache-manager@7.2.10<\/code>, <code>@cacheable\/node-cache@3.1.2<\/code>, <code>ecto@5.0.1<\/code> and <code>@cacheable\/net@2.1.1<\/code>.<\/p>\n<p>StepSecurity said the initial compromise was followed by propagation into hundreds of other packages. Among the namespaces recorded in its investigation were <code>@servicetitan<\/code>, with 141 packages; <code>@onereach<\/code>, with 78; <code>@or-sdk<\/code>, with 74; <code>@ornikar<\/code>, with 42; and <code>@qlik<\/code>, with 28. Smaller affected namespaces included <code>@nebula.js<\/code>, <code>@umacloud<\/code>, <code>@arv-bedrock<\/code>, <code>@deliveroo<\/code>, <code>@picsart<\/code> and <code>@adminide-stack<\/code>. The investigation also recorded 26 additional unscoped packages.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/\">Microsoft&#8217;s security research<\/a> independently described the campaign as a self-propagating worm. Its analysis found that stolen npm publishing credentials could be used to enumerate packages controlled by a compromised identity and publish infected versions without requiring the attacker to manually compromise each package.<\/p>\n<p>The malicious packages typically use an npm <code>preinstall<\/code> lifecycle hook to start the attack. StepSecurity found files including <code>setup.mjs<\/code>, <code>Math_Symbol.js<\/code> and, in later waves, <code>math_init.js<\/code>. The first-stage loader can check whether the Bun JavaScript runtime is present and, when necessary, retrieve a legitimate Bun release before using it to execute the second-stage payload.<\/p>\n<p>StepSecurity measured the main second-stage payload at about 727,680 bytes and found extensive obfuscation and embedded resources. The researchers said the code was designed to collect sensitive information from both developer workstations and automated build environments.<\/p>\n<p>The stolen information can include npm and GitHub credentials, cloud credentials, Kubernetes configuration, HashiCorp Vault material, SSH keys, environment files and other secrets.<\/p>\n<p><a href=\"https:\/\/unit42.paloaltonetworks.com\/\">Palo Alto Networks&#8217; Unit 42 analysis<\/a> independently documented collection attempts involving AWS and other cloud credentials, Docker and Helm configuration, Git credentials, npm and GitHub tokens, PyPI and RubyGems credentials, Terraform state, Vault and Kubernetes credentials, as well as data stored by developer tools.<\/p>\n<p>The campaign also searches for credentials associated with modern AI development tools. StepSecurity identified paths associated with environments including Claude Code, Codex, Cursor, OpenAI, Anthropic, Gemini, OpenClaw, OpenCode and Kiro. The findings show that the attackers were not limiting collection to traditional package-manager or cloud credentials.<\/p>\n<p>One of the more significant techniques identified by researchers involves GitHub Actions runners. Unit 42 found an embedded Python component that can locate the <code>Runner.Worker<\/code> process and inspect its memory for secrets and OpenID Connect credentials. This allows the malware to seek credentials that may exist in memory during a build even when they are not permanently stored as files.<\/p>\n<p>The malware can also use compromised GitHub credentials to modify repositories. StepSecurity observed files such as <code>.vscode\/tasks.json<\/code>, <code>.vscode\/setup.mjs<\/code>, <code>.claude\/settings.json<\/code> and <code>.claude\/setup.mjs<\/code> being used as persistence mechanisms. Unit 42 found that these configurations could execute code through development-tool startup or session hooks, creating another route for malicious code to reach developers working with an affected repository.<\/p>\n<p>ChainDrop also uses blockchain infrastructure to locate command-and-control servers. StepSecurity identified an Ethereum smart contract at <code>0xE1f2395ee43e45A1556EC6438a88c31B83493103<\/code> that stores command-and-control information and can be updated by the operator. The researchers observed <code>npm-cache.com<\/code> among the infrastructure used for data exfiltration.<\/p>\n<p>The use of an Ethereum contract allows the operator to change the infrastructure that infected systems contact without necessarily releasing another version of the malicious package. StepSecurity said the stolen data is compressed and encrypted before transmission and found evidence that the server can return JavaScript to the infected system.<\/p>\n<p>The campaign&#8217;s publishing process also raises concerns about software provenance. StepSecurity found malicious releases that were published through legitimate GitHub Actions workflows and carried valid provenance attestations. That means provenance could show that a package came from the expected build process while the source or release process itself had already been compromised.<\/p>\n<p>This distinction is important because a valid build record does not by itself prove that the code entering the build was authorized. In the ChainDrop investigation, attackers were able to abuse trusted publishing mechanisms after obtaining control of maintainer credentials and development workflows.<\/p>\n<p>StepSecurity also found evidence of the malware executing in public GitHub Actions runs associated with the Backstage project.<\/p>\n<p>The researchers said they identified 15 matching runs, including five of their own test runs and 10 associated with Backstage. They did not find evidence that long-lived repository credentials were stolen from those Backstage runs, because the affected jobs did not contain repository secrets and the GitHub token available to the jobs was ephemeral.<\/p>\n<p>Developers and organizations that may have installed an affected package should establish which versions were present and whether the malicious installation scripts actually executed. Microsoft recommends treating systems that executed affected packages as potentially compromised, rotating exposed credentials from a clean environment and rebuilding affected systems and downstream artifacts from trusted sources.<\/p>\n<p>For the prominent initial packages, StepSecurity listed the following known-good versions: <code>keyv@5.6.0<\/code>, <code>flat-cache@6.1.23<\/code>, <code>file-entry-cache@11.1.5<\/code>, <code>cacheable@2.5.0<\/code>, <code>cacheable-request@13.0.19<\/code>, <code>cache-manager@7.2.9<\/code> and <code>ecto@5.0.0<\/code>.<\/p>\n<p>The incident is part of a broader series of npm supply-chain attacks that have increasingly targeted developer credentials, CI\/CD systems and package publishing workflows.<\/p>\n<p>Microsoft has previously documented campaigns involving malicious npm packages, stolen publishing credentials, CI\/CD runner memory scraping and packages carrying legitimate publishing provenance. Its broader <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/12\/09\/shai-hulud-2-0-guidance-for-detecting-investigating-and-defending-against-the-supply-chain-attack\/\">Shai-Hulud research<\/a> provides context for the techniques that have appeared across this family of attacks.<\/p>\n<p>Researchers have linked ChainDrop technically to the wider Shai-Hulud family, but the available evidence does not establish that a specific previously named group conducted the August campaign. The safest description is therefore a self-propagating npm supply-chain attack that used stolen credentials and compromised publishing workflows to spread across unrelated packages and development environments.<\/p>\n<p>The 444-package figure remains one of the clearest measurements from the incident, but it should be presented as <strong>StepSecurity&#8217;s August 4 snapshot<\/strong>, not as an immutable final total. As researchers continued examining the campaign, different investigations recorded different numbers of packages and versions.<\/p>\n<p>The consistent finding across the research is that ChainDrop was designed to move beyond an individual malicious package and use compromised developer and publishing credentials to create further infections.<\/p>\n<p><strong>References:<\/strong> <a href=\"https:\/\/www.stepsecurity.io\/blog\/chaindrop-npm-worm\">StepSecurity&#8217;s ChainDrop forensic analysis<\/a>; <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/08\/04\/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm\/\">Microsoft Security&#8217;s ChainDrop investigation<\/a>; <a href=\"https:\/\/unit42.paloaltonetworks.com\/\">Palo Alto Networks Unit 42 research<\/a>; <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/12\/09\/shai-hulud-2-0-guidance-for-detecting-investigating-and-defending-against-the-supply-chain-attack\/\">Microsoft&#8217;s Shai-Hulud research<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new npm supply-chain attack has compromised hundreds of JavaScript packages and turned stolen developer credentials into a mechanism for spreading the malware to additional projects. Researchers tracking the campaign have identified 444 unique npm packages and 2,212 compromised versions in one August 4 investigation snapshot, while separate researchers recorded different totals as the campaign [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":6540,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_monsterinsights_skip_tracking":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[164],"tags":[30],"class_list":["post-6539","post","type-post","status-publish","format-standard","has-post-thumbnail","category-tech-updates","tag-cybersecurity"],"share_on_mastodon":{"url":"https:\/\/mastodon.social\/@Areeblog\/117100456368115248","error":""},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>ChainDrop Hits 444 npm Packages in New Self-Propagating Supply-Chain Attack - Aree Blog<\/title>\n<meta name=\"description\" content=\"ChainDrop hits 444 npm packages in a self-propagating attack targeting developer credentials, GitHub and CI systems.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ChainDrop Hits 444 npm Packages in New Self-Propagating Supply-Chain Attack\" \/>\n<meta property=\"og:description\" content=\"ChainDrop hits 444 npm packages in a self-propagating attack targeting developer credentials, GitHub and CI systems.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/\" \/>\n<meta property=\"og:site_name\" content=\"Aree Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-15T16:20:32+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-33.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"739\" \/>\n\t<meta property=\"og:image:height\" content=\"415\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Daniel Chinonso John\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Daniel Chinonso John\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\\\/\"},\"author\":{\"name\":\"Daniel Chinonso John\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/#\\\/schema\\\/person\\\/d972222c55618fb0f4b4c0c11ff52f63\"},\"headline\":\"ChainDrop Hits 444 npm Packages in New Self-Propagating Supply-Chain Attack\",\"datePublished\":\"2026-08-15T16:20:32+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\\\/\"},\"wordCount\":1224,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/images-33.jpeg\",\"keywords\":[\"cybersecurity\"],\"articleSection\":[\"Tech Updates\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/areeblog.com\\\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\\\/\",\"url\":\"https:\\\/\\\/areeblog.com\\\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\\\/\",\"name\":\"ChainDrop Hits 444 npm Packages in New Self-Propagating Supply-Chain Attack - Aree Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/images-33.jpeg\",\"datePublished\":\"2026-08-15T16:20:32+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/#\\\/schema\\\/person\\\/d972222c55618fb0f4b4c0c11ff52f63\"},\"description\":\"ChainDrop hits 444 npm packages in a self-propagating attack targeting developer credentials, GitHub and CI systems.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/areeblog.com\\\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\\\/#primaryimage\",\"url\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/images-33.jpeg\",\"contentUrl\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/images-33.jpeg\",\"width\":739,\"height\":415,\"caption\":\"ChainDrop Hits 444 npm Packages in New Self-Propagating Supply-Chain Attack\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/areeblog.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ChainDrop Hits 444 npm Packages in New Self-Propagating Supply-Chain Attack\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/#website\",\"url\":\"https:\\\/\\\/areeblog.com\\\/\",\"name\":\"Aree Blog\",\"description\":\"Unfiltered Perspectives, Unstoppable Insights\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/areeblog.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/#\\\/schema\\\/person\\\/d972222c55618fb0f4b4c0c11ff52f63\",\"name\":\"Daniel Chinonso John\",\"description\":\"Daniel Chinonso John is a web designer, penetration tester, and founder of Aree Tech. He writes clear, actionable posts at the intersection of productivity, AI, cybersecurity, and blogging to help readers get things done.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/daniel-john-45183a169\\\/\"],\"url\":\"https:\\\/\\\/areeblog.com\\\/author\\\/danojohn55gmail-com\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"ChainDrop Hits 444 npm Packages in New Self-Propagating Supply-Chain Attack - Aree Blog","description":"ChainDrop hits 444 npm packages in a self-propagating attack targeting developer credentials, GitHub and CI systems.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/","og_locale":"en_US","og_type":"article","og_title":"ChainDrop Hits 444 npm Packages in New Self-Propagating Supply-Chain Attack","og_description":"ChainDrop hits 444 npm packages in a self-propagating attack targeting developer credentials, GitHub and CI systems.","og_url":"https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/","og_site_name":"Aree Blog","article_published_time":"2026-08-15T16:20:32+00:00","og_image":[{"width":739,"height":415,"url":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-33.jpeg","type":"image\/jpeg"}],"author":"Daniel Chinonso John","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Daniel Chinonso John","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/#article","isPartOf":{"@id":"https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/"},"author":{"name":"Daniel Chinonso John","@id":"https:\/\/areeblog.com\/#\/schema\/person\/d972222c55618fb0f4b4c0c11ff52f63"},"headline":"ChainDrop Hits 444 npm Packages in New Self-Propagating Supply-Chain Attack","datePublished":"2026-08-15T16:20:32+00:00","mainEntityOfPage":{"@id":"https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/"},"wordCount":1224,"commentCount":0,"image":{"@id":"https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/#primaryimage"},"thumbnailUrl":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-33.jpeg","keywords":["cybersecurity"],"articleSection":["Tech Updates"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/","url":"https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/","name":"ChainDrop Hits 444 npm Packages in New Self-Propagating Supply-Chain Attack - Aree Blog","isPartOf":{"@id":"https:\/\/areeblog.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/#primaryimage"},"image":{"@id":"https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/#primaryimage"},"thumbnailUrl":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-33.jpeg","datePublished":"2026-08-15T16:20:32+00:00","author":{"@id":"https:\/\/areeblog.com\/#\/schema\/person\/d972222c55618fb0f4b4c0c11ff52f63"},"description":"ChainDrop hits 444 npm packages in a self-propagating attack targeting developer credentials, GitHub and CI systems.","breadcrumb":{"@id":"https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/#primaryimage","url":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-33.jpeg","contentUrl":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-33.jpeg","width":739,"height":415,"caption":"ChainDrop Hits 444 npm Packages in New Self-Propagating Supply-Chain Attack"},{"@type":"BreadcrumbList","@id":"https:\/\/areeblog.com\/chaindrop-hits-444-npm-packages-in-new-self-propagating-supply-chain-attack\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/areeblog.com\/"},{"@type":"ListItem","position":2,"name":"ChainDrop Hits 444 npm Packages in New Self-Propagating Supply-Chain Attack"}]},{"@type":"WebSite","@id":"https:\/\/areeblog.com\/#website","url":"https:\/\/areeblog.com\/","name":"Aree Blog","description":"Unfiltered Perspectives, Unstoppable Insights","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/areeblog.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/areeblog.com\/#\/schema\/person\/d972222c55618fb0f4b4c0c11ff52f63","name":"Daniel Chinonso John","description":"Daniel Chinonso John is a web designer, penetration tester, and founder of Aree Tech. He writes clear, actionable posts at the intersection of productivity, AI, cybersecurity, and blogging to help readers get things done.","sameAs":["https:\/\/www.linkedin.com\/in\/daniel-john-45183a169\/"],"url":"https:\/\/areeblog.com\/author\/danojohn55gmail-com\/"}]}},"jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":6735,"url":"https:\/\/areeblog.com\/researchers-find-ai-coding-agents-can-turn-llms-txt-into-a-software-supply-chain-attack-surface\/","url_meta":{"origin":6539,"position":0},"title":"Researchers Find AI Coding Agents Can Turn llms.txt Into a Software Supply-Chain Attack Surface","author":"Daniel Chinonso John","date":"September 3, 2026","format":false,"excerpt":"Security researchers have demonstrated that AI coding agents can execute unclaimed software packages referenced by trusted-looking website documentation, creating a potential software supply-chain attack path for companies using autonomous coding tools. The research focused on llms.txt and llms-full.txt, machine-readable files increasingly published by websites to summarize their content and structure\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"Researchers Find AI Coding Agents Can Turn llms.txt Into a Software Supply-Chain Attack Surface","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260903-WA0006.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260903-WA0006.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260903-WA0006.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260903-WA0006.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/IMG-20260903-WA0006.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":6302,"url":"https:\/\/areeblog.com\/how-hallucinated-packages-become-an-attack-vector\/","url_meta":{"origin":6539,"position":1},"title":"How Hallucinated Packages Become an Attack Vector","author":"Daniel Chinonso John","date":"July 11, 2026","format":false,"excerpt":"Trust is becoming one of the most valuable\u2014and most dangerous\u2014currencies in software development. Every time an AI coding assistant suggests a library, most developers assume it exists. That assumption is increasingly being weaponized, not by breaking into software repositories, but by waiting for AI to imagine a package that has\u2026","rel":"","context":"In &quot;Cybersecurity&quot;","block_context":{"text":"Cybersecurity","link":"https:\/\/areeblog.com\/category\/cybersecurity\/"},"img":{"alt_text":"How Hallucinated Packages Become an Attack Vector","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0002.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0002.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0002.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0002.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0002.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":6305,"url":"https:\/\/areeblog.com\/risks-for-developers-using-ai-generated-code\/","url_meta":{"origin":6539,"position":2},"title":"Risks for Developers Using AI-Generated Code","author":"Daniel Chinonso John","date":"July 12, 2026","format":false,"excerpt":"Writing software has never been faster. A single prompt can generate authentication systems, database queries, API integrations, and even complete applications in minutes. But every shortcut comes with a trade-off, and in software development, that trade-off is often hidden until something breaks\u2014or worse, gets exploited. AI coding assistants like ChatGPT,\u2026","rel":"","context":"In &quot;Cybersecurity&quot;","block_context":{"text":"Cybersecurity","link":"https:\/\/areeblog.com\/category\/cybersecurity\/"},"img":{"alt_text":"Risks for Developers Using AI-Generated Code","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0003.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0003.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0003.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0003.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260712-WA0003.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":5850,"url":"https:\/\/areeblog.com\/how-malicious-vs-code-extensions-are-used-to-steal-developer-credentials\/","url_meta":{"origin":6539,"position":3},"title":"How Malicious VS Code Extensions Are Used to Steal Developer Credentials","author":"Daniel Chinonso John","date":"January 21, 2026","format":false,"excerpt":"Developers trust their tools. That trust is what makes Visual Studio Code a productive workspace, and what attackers are quietly exploiting. Recent security research shows a worrying trend: threat actors are slipping malicious code into what look like helpful VS Code extensions. When a developer installs one of these packages,\u2026","rel":"","context":"In &quot;Cybersecurity&quot;","block_context":{"text":"Cybersecurity","link":"https:\/\/areeblog.com\/category\/cybersecurity\/"},"img":{"alt_text":"How Malicious VS Code Extensions Are Used to Steal Developer Credentials","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260121-WA0002.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":6839,"url":"https:\/\/areeblog.com\/google-says-hackers-are-using-ai-agents-to-run-multi-stage-attacks-with-little-human-input\/","url_meta":{"origin":6539,"position":4},"title":"Google Says Hackers Are Using AI Agents to Run Multi-Stage Attacks With Little Human Input","author":"Daniel Chinonso John","date":"September 9, 2026","format":false,"excerpt":"Hackers are increasingly using artificial intelligence to automate multiple stages of cyberattacks, with Google Threat Intelligence Group reporting that some attackers have moved beyond simple prompting to AI-driven workflows capable of scanning targets, troubleshooting failures and harvesting credentials with limited human involvement. In a report published September 8, 2026, Google\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"Google Says Hackers Are Using AI Agents to Run Multi-Stage Attacks With Little Human Input","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/images-55.jpeg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/images-55.jpeg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/images-55.jpeg?resize=525%2C300&ssl=1 1.5x"},"classes":[]},{"id":6701,"url":"https:\/\/areeblog.com\/shadow-ai-is-moving-into-approved-enterprise-tools\/","url_meta":{"origin":6539,"position":5},"title":"Shadow AI Is Moving Into Approved Enterprise Tools","author":"Samuel Ogori","date":"August 31, 2026","format":false,"excerpt":"Security teams are facing a newer form of shadow AI as approved enterprise applications increasingly gain the ability to run extensions, connect to outside services and follow instructions supplied by software repositories. An analysis published by The Hacker News on August 31 argues that the security problem is no longer\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"Shadow AI Is Now Hiding Inside Sanctioned AI Tools","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/IMG-20260831-WA0027.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/IMG-20260831-WA0027.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/IMG-20260831-WA0027.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/IMG-20260831-WA0027.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/IMG-20260831-WA0027.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]}],"jetpack_featured_media_url":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-33.jpeg","_links":{"self":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts\/6539","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/comments?post=6539"}],"version-history":[{"count":1,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts\/6539\/revisions"}],"predecessor-version":[{"id":6541,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts\/6539\/revisions\/6541"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/media\/6540"}],"wp:attachment":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/media?parent=6539"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/categories?post=6539"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/tags?post=6539"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}