INCIDENT EVIDENCE GRAPH

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm credentials to backdoor co-owned packages totaling over 1.3 billion monthly downloads.

Primary evidence

  1. Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

中文