← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 4, 2026 · 23:46via Microsoft Security Blog

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

Brief

In this article

  • Attack chain overview
  • Mitigation and protection guidance
  • Indicators of compromise (IOC)
  • Microsoft Defender XDR detections
  • Advanced hunting queries
  • Learn more

Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting more than 400 packages across multiple unrelated publishers, including packages associated with major enterprise software ecosystems such as keyv, flat-cache, cache-manager, and others.

The malicious releases contain a Mini Shai-Hulud variant, a self-propagating credential-stealing worm delivered through a large, heavily obfuscated Bun-based JavaScript payload. The malware typically executes automatically through an npm preinstall lifecycle hook before package installation completes.

Read more on Microsoft Security Blog