agent-postmortems a structured database of real AI-agent failures

← all incidents

incident high confidence: confirmed status: factual

ChainDrop npm worm poisoned 400+ packages and self-propagated via Claude Code and VS Code auto-run hooks

2026-chaindrop-npm-worm · 2026-08-04

ChainDrop is a self-propagating npm supply-chain worm that poisoned 400+ packages (including keyv and cacheable-request, downloaded hundreds of millions of times weekly), stole cloud and CI credentials, and republished malware under them. Beyond package lifecycle hooks, it planted hooks in Claude Code and VS Code that run automatically when a teammate opens a poisoned repository.

System

Framework
npm ecosystem; Claude Code and VS Code (agent auto-run hooks)
Tools
npm, claude-code, vscode, ci
Autonomy
supervised-autonomous

Classification

Primary class
supply-chain-compromise
Chain
supply-chain-compromise/dependency → unsafe-action/unauthorized-write
Attack vector
supply-chain
Causation
entity: human · intentionality: intentional · timing: post-deployment

Trigger

Installing a poisoned package ran a preinstall lifecycle hook that downloaded a standalone Bun runtime and roughly 710 KB of obfuscated second-stage code, which harvested cloud and CI credentials and used them to republish malware to more packages. The worm also planted hooks in Claude Code and VS Code that execute automatically the moment a teammate opens a poisoned repository, spreading through tools developers use all day.

Root cause

Package managers and AI coding agents execute repository-provided hooks and lifecycle scripts automatically, and stolen credentials let the worm republish under trusted names. Using mechanisms the tools ship on purpose (lifecycle hooks, editor/agent auto-run), the worm propagated without tripping malware-focused defenses.

Contributing factors

  • npm lifecycle hooks and editor/agent auto-run features execute untrusted repository content by default.
  • Harvested cloud/CI credentials allowed trusted-name republishing.
  • Widely depended-on packages (keyv, cacheable-request) amplified reach.

Detection

Analysed and disclosed by Microsoft Security and Palo Alto Unit 42 (and others) in August 2026, linking it to the Shai-Hulud self-propagating-worm lineage.

Recovery

Malicious package versions were removed and compromised credentials rotated; guidance centred on disabling automatic lifecycle/hook execution and pinning and reviewing dependencies.

Prevention

Disable automatic execution of lifecycle scripts and editor/agent hooks from untrusted repositories; require explicit approval before an agent runs repository-provided hooks; pin and verify dependencies; scope and rotate CI credentials; monitor for credential-republish patterns.

Blast radius

Data
Cloud and CI credentials were harvested and reused to republish malware; 400+ packages across 2,200+ malicious versions were affected, including keyv and cacheable-request. credentials
User harm
Credential theft and malware distribution across the npm ecosystem; affected packages are collectively downloaded hundreds of millions of times per week. economic
Scope
400+ npm packages (2,200+ malicious versions); hundreds of millions of weekly downloads
Reversibility
irreversible

References

OWASP LLM
LLM03 LLM06
Tags
supply-chain npm-worm self-propagating claude-code vscode credential-theft

Sources

Cite this incident

@misc{2026-chaindrop-npm-worm,
  title = {ChainDrop npm worm poisoned 400+ packages and self-propagated via Claude Code and VS Code auto-run hooks},
  year = {2026},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2026-chaindrop-npm-worm/}
}