Home / Companies / Semgrep / Blog / Post Details
Content Deep Dive

It’s not npm-ver yet: NPM worm Chaindrop hits 400+ packages including jaredwray, servicetitan, ornikar, qlik and nebula.js

Blog post from Semgrep

Post Details
Company
Date Published
Author
Katie Paxton-Fear
Word Count
2,822
Company Posts That Month
2
Language
English
Hacker News Points
-
Post removed?
No
Summary

The "Worms are Back" ChainDrop campaign is an automated npm compromise observed on August 4, 2026, characterized by the republishing of legitimate packages under hijacked maintainer credentials. This approach led to 1,557 malicious versions appearing within about two hours. The compromised packages include obfuscated loader files integrated into the preinstall lifecycle hook, allowing code execution during dependency resolution. The second stage of this malware targets developer workstations and CI/CD runners to harvest credentials like npm authentication tokens, cloud provider credentials, SSH private keys, and CI secrets. The worm propagates by utilizing harvested npm tokens and employs an Ethereum dead-drop for command-and-control infrastructure, enabling operators to reassign infrastructure without hardcoding domains. Semgrep users are advised to scan projects for potential impacts, while indicators of compromise include specific file hashes, install hooks, and command-and-control resolution methods.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 4 584 99 52 -76%
Serverless 3 149 44 30 -80%
MCP 2 1,562 186 99 -80%
Kubernetes 1 634 79 44 -75%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.