ChainDrop supply chain compromise: Anatomy of a self-propagating worm
Brief
In this article
- Attack chain overview
- Mitigation and protection guidance
- Indicators of compromise (IOC)
- Microsoft Defender XDR detections
- Advanced hunting queries
- Learn more
Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting more than 400 packages across multiple unrelated publishers, including packages associated with major enterprise software ecosystems such as keyv, flat-cache, cache-manager, and others.
The malicious releases contain a Mini Shai-Hulud variant, a self-propagating credential-stealing worm delivered through a large, heavily obfuscated Bun-based JavaScript payload. The malware typically executes automatically through an npm preinstall lifecycle hook before package installation completes.
