TI Mindmap HUB
Threat Intelligence Report

ChainDrop: Inside a Self-Propagating npm Worm

๐Ÿ“… August 7, 2026 ๐Ÿ“ฐ unit42.paloaltonetworks.com ๐Ÿ” 0 CVE(s) referenced

The ChainDrop npm worm is a highly sophisticated, self-propagating supply chain attack that infected hundreds of popular packages, stealthily harvesting sensitive credentials and spreading across developer workstations, CI pipelines, and cloud environments while dynamically controlling its infrastructure via blockchain, making detection and containment especially challenging.

vendor

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

๐Ÿ” Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

๐Ÿ“Š Visual Mindmap
๐ŸŽฏ IOC Extraction
โš”๏ธ MITRE ATT&CK TTPs
๐Ÿ“ฆ STIX 2.1 Bundle