{
  "id": 174239,
  "title": "New ChainDrop worm poisons over 1,300 npm packages, Keyv and Cacheable among those hit",
  "url": "https://urgent.news/2026/08/05/new-chaindrop-worm-poisons-over-1-300-npm-packages-keyv-and-cacheable",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-05T11:05:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/new-chaindrop-worm-poisons-over-1-300-npm-packages-keyv-and-cacheable-among-those-hit"
  },
  "original_language": "en",
  "account": "Security researchers Aikido have uncovered a new Shai-Hulud variant, dubbed ChainDrop, that has infected over 1,300 npm packages. This malicious worm is designed to steal developer and cloud credentials, exfiltrating them to a public GitHub repository. The attack targeted popular JavaScript libraries such as Keyv, Cacheable, flat-cache, and file-entry-cache, all of which have a combined total of 2 billion monthly downloads. Aikido discovered that attackers compromised GitHub accounts associated with these libraries, allowing them to push tainted releases directly into the projects' main branches. The malware then proceeded to generate additional package releases, spreading the infection further. Affected packages were found to have stolen local configuration files, GitHub PATs, workflow tokens, npm tokens, GitHub Actions secrets, AWS credentials, Kubernetes secrets, and more. Researchers advise system administrators to treat affected developer workstations or CI/CD runners as compromised, even after removing the tainted packages.",
  "summary": "Another Shai-Hulud variant hits npm packages, worming its way into hundreds of packages.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}