Skip to content
archivesupply chain · 06 Aug 2026 · 00:00 UTC

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

last 60 dispatches · spectrum

Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm credentials to backdoor co-owned packages totaling over 1.3 billion monthly downloads.

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected