npm Supply-Chain Attack Tracker
Software supply-chain attacks on npm went from rare to routine in 2026. This is a living list of the incidents PlayCISO has analysed first-hand — the self-replicating Shai-Hulud / ChainDrop worm family and the credential stealers riding the same playbook. Every row links to a full breakdown with named sources, the affected versions, and what a security leader should actually do. 4 incidents are tracked today.
| Disclosed | Package | Family | What it did | Safe version |
|---|---|---|---|---|
| 2026-10-08 | tensorlake@0.5.144npm | Shai-Hulud / ChainDrop | A preinstall setup.mjs skips CI, runs a Bun payload that steals GitHub, npm, cloud, Kubernetes and Vault tokens, and republishes itself into the victim’s packages. A gh-token-monitor service wipes the home directory if the stolen token is revoked. | 0.5.143 |
| 2026-10-05 | @subql/common@5.8.3npm | Shai-Hulud / ChainDrop | A postinstall credential stealer (base64 + XOR + gzip, hidden as a manifest-cache reader) runs on install and on import, harvesting .npmrc, .env, AWS keys, SSH keys, kubeconfig and GitHub Actions runner memory. | 5.8.2 |
| 2026-09-18 | apexacc-clinpm | Infostealer | Elastic Security Labs flagged a Windows infostealer shipped inside the apexacc-cli npm package, exfiltrating developer credentials and browser data. | Remove |
| 2026-07-16 | Suno (Shai-Hulud wave)npm | Shai-Hulud / ChainDrop | An earlier Shai-Hulud self-propagating wave hitting the npm ecosystem; the write-up covers what it did and the lessons for security leaders. | See analysis |
Showing 4 of 4 tracked incidents. Each links to PlayCISO's full analysis with sources.
The defender's playbook (true for every row)
- Default-deny install scripts. Run installs with
--ignore-scriptsand allowlist the few packages that genuinely need lifecycle hooks. This neuters the entire "runs on install" class. - Remove persistence before you revoke. Some variants wipe the machine when a stolen token is revoked. Find and remove the implant first, then rotate credentials.
- Pin and verify. Commit lockfiles with integrity hashes and require provenance on what you publish and consume.
- Fence CI runners. Short-scope permissions, prefer ephemeral identities, and egress-restrict runners so a compromised step cannot reach an exfiltration domain.
What this tracker is
- A living list of npm and PyPI supply-chain attacks PlayCISO has analysed, newest first, each linking to the full breakdown with named sources.
- 4 incidents are tracked today; the Shai-Hulud / ChainDrop worm family accounts for most of them.
- The common pattern in 2026: a lifecycle hook (preinstall / postinstall) runs on install, steals developer and CI credentials, and republishes itself through a stolen npm token.
- The durable fix is not token rotation alone — it is default-denying install scripts, pinning with integrity hashes, and fencing CI runners.
- Scan your own manifests free with the PlayCISO NPM Scanner and Package Scanner.
Frequently asked questions
What is the Shai-Hulud npm worm?
Shai-Hulud is a family of self-replicating npm worms first seen in 2025 and resurging through 2026 (the keyv wave, the @subql / ChainDrop wave, and the tensorlake compromise). A malicious package runs code on install, steals developer and CI credentials, and — with a stolen npm token — injects itself into the victim’s own packages and republishes them, so every infected maintainer becomes a new source of infection.
How do I know if I am affected by one of these packages?
Run npm ls <package> across every repository and developer machine, and search your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock) for the malicious version. Do not forget transitive dependencies and anything an AI coding agent installed. Treat any host where the install script ran as compromised.
Why does rotating my npm token not stop the worm?
The most durable variants abuse GitHub Actions ephemeral OIDC tokens minted per workflow run rather than a static secret, and some (like tensorlake) install a dead-man’s switch that wipes the home directory when a stolen token is revoked. Remove persistence first, then rotate; the lasting defence is blocking install-time scripts by default and fencing CI runners.
Is this tracker complete?
No. It covers the incidents PlayCISO has published a full analysis of, so you get a cited breakdown behind every row rather than a raw feed. It is updated as new attacks are analysed.