


Perceptive Security
SOC/SIEM Consultancy

ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2
Published:
4 August 2026 at 11:18:34
Alert date:
4 August 2026 at 12:01:53
Source:
stepsecurity.io
Supply Chain & Dependencies, Ransomware & Malware, Identity & Access, Web Technologies
ChainDrop is a self-propagating npm worm that compromises npm packages by stealing maintainer credentials and publishing malicious versions. The malware targets CI/CD pipelines to harvest credentials from build environments. It leverages Bun runtime and uses Ethereum blockchain as a dead-drop mechanism for command-and-control (C2) communications, making detection harder. Dozens of npm packages have been affected by this supply chain attack. The worm spreads autonomously by using stolen credentials to publish compromised versions of legitimate packages. Organizations using affected npm packages in their pipelines are at risk of credential theft and further compromise. Immediate action is recommended to identify and remove affected packages.
Technical details
Mitigation steps:
Affected products:
npm
Bun
CI/CD pipelines
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
