The PolySwarm Blog

Analyze suspicious files and URLs, at scale, millions of times per day. Get real-time threat intel from a crowdsourced network of security experts and antivirus companies competing to protect you.

Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack

Aug 10, 2026, 3:15:02 PM / by The Hivemind posted in Threat Bulletin, npm malware, Software Supply Chain Security, Mini Shai-Hulud, JavaScript malware, GitHub Actions OIDC, npm supply chain attack

0 Comments

Related Families: Mini Shai-Hulud, ChainDrop

Executive Summary

Industry researchers identified a large-scale software supply chain attack involving more than 400 compromised npm packages distributed across multiple unrelated publishers. The campaign delivers a new variant of the Mini Shai-Hulud malware, dubbed ChainDrop, through malicious preinstall lifecycle scripts, enabling credential theft, cloud and infrastructure enumeration, repository compromise, and automated propagation using stolen npm publishing credentials. By targeting both developer workstations and CI/CD environments, the campaign demonstrates how modern software supply chain attacks increasingly leverage trusted developer identities to compromise downstream software ecosystems.

Read More

Miasma Expands Software Supply Chain Attacks Through Compromised CI/CD Infrastructure

Jun 15, 2026, 2:57:00 PM / by The Hivemind posted in Threat Bulletin, Supply Chain Attack, Mini Shai-Hulud, GitHub Actions, Miasma, npm, SLSA, Open Source Security, CI/CD Security

0 Comments

Verticals Targeted: Software Development
Regions Targeted: Global
Related Families: Miasma, Mini Shai-Hulud

Executive Summary

Miasma is a software supply chain malware campaign targeting developer ecosystems, CI/CD pipelines, GitHub repositories, and open-source package registries. Earlier this month, researchers identified a compromise affecting at least 32 packages and more than 90 malicious package versions published under the @redhat-cloud-services npm namespace. Collectively, the affected packages averaged approximately 80,000 weekly downloads. The campaign abused GitHub Actions OpenID Connect (OIDC) trusted publishing workflows to distribute malicious packages with valid provenance attestations, demonstrating how legitimate software supply chain trust mechanisms can be weaponized following compromise of upstream development infrastructure. Miasma harvests GitHub credentials, cloud identities, CI/CD secrets, SSH keys, and other sensitive developer assets that could facilitate compromise of additional repositories, software packages, and development environments. The campaign highlights the increasing sophistication of attacks targeting software development infrastructure rather than traditional end-user systems.

Read More

Subscribe to Email Updates

Lists by Topic

see all

Posts by Topic

See all

Recent Posts