It’s not npm-ver yet: NPM worm Chaindrop hits 400+ packages including jaredwray, servicetitan, ornikar, qlik and nebula.js
Blog post from Semgrep
The "Worms are Back" ChainDrop campaign is an automated npm compromise observed on August 4, 2026, characterized by the republishing of legitimate packages under hijacked maintainer credentials. This approach led to 1,557 malicious versions appearing within about two hours. The compromised packages include obfuscated loader files integrated into the preinstall lifecycle hook, allowing code execution during dependency resolution. The second stage of this malware targets developer workstations and CI/CD runners to harvest credentials like npm authentication tokens, cloud provider credentials, SSH private keys, and CI secrets. The worm propagates by utilizing harvested npm tokens and employs an Ethereum dead-drop for command-and-control infrastructure, enabling operators to reassign infrastructure without hardcoding domains. Semgrep users are advised to scan projects for potential impacts, while indicators of compromise include specific file hashes, install hooks, and command-and-control resolution methods.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 4 | 584 | 99 | 52 | -76% |
| Serverless | 3 | 149 | 44 | 30 | -80% |
| MCP | 2 | 1,562 | 186 | 99 | -80% |
| Kubernetes | 1 | 634 | 79 | 44 | -75% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.