Shai-Hulud npm worm variant 'ChainDrop' poisons 444 packages
Story essentials
ChainDrop malware operators
Global (npm ecosystem)
August 4, 2026
This page is produced by collecting and structuring multiple public reports. Sections based only on reporting or testimony affect the displayed assessment, and the page is updated when new information is identified.
About this article
COMPAMIR Editorial Team
The COMPAMIR editorial team brings together public reporting and links to the original coverage. We update the page as new information emerges.
Read our editorial policy- Earlier version 18/15/2026, 11:50:22 PM
A new Shai-Hulud variant named 'ChainDrop' has infected 444 npm packages. The malware spreads via tarballs and injects startup hooks into repository configurations. It targets npm tokens, GitHub credentials, and environment variables to exfiltrate data. Infection can occur simply by opening a compromised Git branch in VS Code or Claude Code.
Read next
Prioritized by shared people, places, and events.
OpenAI Launches 'Dots' AI Agent Amid Domain Name Controversy
OpenAI released an AI agent called 'Dots'. Elon Musk's xAI owns the 'dot.com' domain, which redirects to the Grok chatbot. Speculation suggests the domain acquisition may be a prank by Musk.