INCIDENT EVIDENCE GRAPH
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm credentials to backdoor co-owned packages totaling over 1.3 billion monthly downloads.
- Victim: keyv maintainer and co-owned npm packages
- Actor: Attackers
- Exploit: CHAINDROP worm
- Method: Stolen npm credentials were used to backdoor co-owned packages