Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

Reported 05 Aug 2026 by otx · Severity: medium

On August 4, 2026, a sophisticated supply chain attack compromised the keyv npm package maintainer, deploying CHAINDROP, a self-propagating worm that automatically backdoors packages using stolen npm credentials. Over 400 npm packages were infected, affecting more than 1.3 billio