ChainDrop npm worm poisoned 400+ packages and self-propagated via Claude Code and VS Code auto-run hooks
2026-chaindrop-npm-worm · 2026-08-04
ChainDrop is a self-propagating npm supply-chain worm that poisoned 400+ packages (including keyv and cacheable-request, downloaded hundreds of millions of times weekly), stole cloud and CI credentials, and republished malware under them. Beyond package lifecycle hooks, it planted hooks in Claude Code and VS Code that run automatically when a teammate opens a poisoned repository.
System
- Framework
- npm ecosystem; Claude Code and VS Code (agent auto-run hooks)
- Tools
- npm, claude-code, vscode, ci
- Autonomy
- supervised-autonomous
Classification
- Primary class
- supply-chain-compromise
- Chain
- supply-chain-compromise/dependency → unsafe-action/unauthorized-write
- Attack vector
- supply-chain
- Causation
- entity: human · intentionality: intentional · timing: post-deployment
Trigger
Installing a poisoned package ran a preinstall lifecycle hook that downloaded a standalone Bun runtime and roughly 710 KB of obfuscated second-stage code, which harvested cloud and CI credentials and used them to republish malware to more packages. The worm also planted hooks in Claude Code and VS Code that execute automatically the moment a teammate opens a poisoned repository, spreading through tools developers use all day.
Root cause
Package managers and AI coding agents execute repository-provided hooks and lifecycle scripts automatically, and stolen credentials let the worm republish under trusted names. Using mechanisms the tools ship on purpose (lifecycle hooks, editor/agent auto-run), the worm propagated without tripping malware-focused defenses.
Contributing factors
- npm lifecycle hooks and editor/agent auto-run features execute untrusted repository content by default.
- Harvested cloud/CI credentials allowed trusted-name republishing.
- Widely depended-on packages (keyv, cacheable-request) amplified reach.
Detection
Analysed and disclosed by Microsoft Security and Palo Alto Unit 42 (and others) in August 2026, linking it to the Shai-Hulud self-propagating-worm lineage.
Recovery
Malicious package versions were removed and compromised credentials rotated; guidance centred on disabling automatic lifecycle/hook execution and pinning and reviewing dependencies.
Prevention
Disable automatic execution of lifecycle scripts and editor/agent hooks from untrusted repositories; require explicit approval before an agent runs repository-provided hooks; pin and verify dependencies; scope and rotate CI credentials; monitor for credential-republish patterns.
Blast radius
- Data
- Cloud and CI credentials were harvested and reused to republish malware; 400+ packages across 2,200+ malicious versions were affected, including keyv and cacheable-request. credentials
- User harm
- Credential theft and malware distribution across the npm ecosystem; affected packages are collectively downloaded hundreds of millions of times per week. economic
- Scope
- 400+ npm packages (2,200+ malicious versions); hundreds of millions of weekly downloads
- Reversibility
- irreversible
References
- OWASP LLM
- LLM03 LLM06
- Tags
- supply-chain npm-worm self-propagating claude-code vscode credential-theft
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2026-chaindrop-npm-worm/
@misc{2026-chaindrop-npm-worm,
title = {ChainDrop npm worm poisoned 400+ packages and self-propagated via Claude Code and VS Code auto-run hooks},
year = {2026},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2026-chaindrop-npm-worm/}
}