Threat reportSupply ChainTL-2026-3214
ChainDrop npm Worm and PolinRider DPRK-Linked Operation Use Blockchain C2 to Steal Cloud and CI/CD Credentials
ChainDrop npm Worm and PolinRider DPRK-Linked Operation Use (TL-2026-3214), also tracked as ChainDrop, is a high-severity supply-chain compromise, first published 2026-10-10. It is attributed to PolinRider (North Korea) with medium confidence, affects npm ecosystem keyv, cacheable-request, flat-cache, cacheable, maps to 19 MITRE ATT&CK techniques (T1003.007, T1005, T1027), and is covered by 9 detection rules and 30 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 19MITRE ATT&CK
- Actors
- 3PolinRider
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 30Indicators of compromise
Key facts for TL-2026-3214
- Threat ID
- TL-2026-3214
- Also known as
- ChainDrop, PolinRider, Shai-Hulud: Here We Go Again, EtherHiding
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- PolinRider, WageMole, ChainDrop operator unattributed
- Attribution confidence
- MEDIUM
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, finance, cryptocurrency, cloud-services
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in ChainDrop npm Worm and PolinRider DPRK-Linked Operation Use
Malware and tooling: BeaverTail - S1246, DEV#POPPER, InvisibleFerret - S1245, Shai-Hulud
How ChainDrop npm Worm and PolinRider DPRK-Linked Operation Use works
ChainDrop is a Shai-Hulud-lineage self-propagating npm worm that compromised 400+ packages (including keyv and cacheable-request) and steals npm/GitHub tokens, SSH keys, cloud, Kubernetes and CI/CD OIDC credentials, resolving its C2 through an Ethereum smart contract. PolinRider is a DPRK-linked (Contagious Interview / Famous Chollima) multi-ecosystem operation that hides obfuscated JavaScript loaders in repository config files and fake .woff2 fonts and resolves payloads from TRON, Aptos and BSC dead drops.
ChainDrop (Unit 42, Elastic Security Labs, Aug 2026) is a cross-platform npm worm sharing code lineage with Shai-Hulud (PBKDF2 decoder, Bun 1.3.13 runtime, _NODE_RUNTIME_INIT pattern, npm self-propagation). On 2026-08-04 the maintainer of keyv was compromised and every subpackage of the keyv monorepo was backdoored with a setup.mjs dropper delivered through a package.json preinstall hook. The dropper downloads a Bun runtime and launches an obfuscated credential harvester (Math_Symbol.js in the keyv monorepo, math_init.js in worm-propagated packages). Over 400 unique npm packages were affected, including keyv (600M+ monthly downloads), flat-cache (~580M), cacheable-request (137M+), cacheable (30M+) and cache-manager (16M+). New malicious versions were published within 6-70 minutes of each compromise.
The payload is obfuscated in three layers (Base91 with per-function alphabets and array rotation; a PBKDF2-SHA256 byte-permutation cipher; AES-256-GCM+gzip blobs holding helpers, persistence installers, a memory scraper and workflow templates). It exits silently on Russian locale. It harvests AWS/Azure/GCP/Alibaba credentials, npm and GitHub tokens, SSH keys, Docker/Helm/Git configs, Vault tokens, Kubernetes service-account tokens and kubeconfigs, Terraform state, Jenkins credentials, .env/.netrc files, crypto-wallet files, shell histories and AI coding tool configurations. On GitHub Actions runners it parses /proc/<pid>/mem of Runner.Worker to extract ephemeral OIDC tokens and secrets. Loot is gzip-compressed, AES-256-GCM encrypted with a key RSA-wrapped under an attacker public key, and sent to a C2 endpoint (/router) whose domain is read at runtime from the Ethereum StringListStore contract 0xE1f2395ee43e45A1556EC6438a88c31B83493103 (EtherHiding), with GitHub commit-message markers as a fallback channel and public victim-owned exfiltration repositories (description 'Shai-Hulud: Here We Go Again', Dune-themed names). The worm propagates only when it finds an npm token with package write permission that can publish without 2FA; in the opensearch-js path it abuses GitHub Actions OIDC trusted publishing to mint genuine Sigstore provenance for a malicious dependency (@opensearch/setup). Persistence is planted into project and IDE automation: .vscode/tasks.json (folderOpen), .claude/settings.json (SessionStart hook), .claude/setup.mjs and .vscode/setup.mjs, committed to up to 50 branches per accessible repository as claude@users.noreply.github.com with message 'chore: update config'. Attribution is unclear (TeamPCP adaptation or a separate group reusing the published Shai-Hulud toolkit).
PolinRider (OpenSourceMalware, Socket, Unit 42) is a DPRK-linked operation tied to the Lazarus / Contagious Interview / Famous Chollima cluster (Unit 42 links it to Alluring Pisces). It was disclosed 2026-03-08 with 675 repositories and grew to 1,951 repositories across 1,047 owners by April 2026, later spreading to Go modules (80+), Packagist (10 packages) and npm (162 malicious artifacts across 108 packages by July 2026), with PyPI repositories and Chrome extensions also affected. Obfuscated JavaScript loaders (four-layer string shuffling; markers rmcej%otb% and later Cot%3t=shtP) are appended to config files (postcss.config.mjs, tailwind.config.js, eslint.config.mjs, next.config.mjs, vite.config.js), hidden in fake .woff2 font files, or launched by .vscode/tasks.json with runOn folderOpen fetching from Vercel-hosted bootstrap hosts. Next-stage payloads are fetched from blockchain dead drops (TRON, Aptos, Binance Smart Chain; TxDataHiding and NullReceiver techniques), XOR-decrypted and run via eval() in detached Node processes. Propagation and anti-forensics use temp_auto_push.bat to rewrite git history with anti-dated commits and force-pushes, and compromised maintainer accounts (e.g. Xpos587, 2026-06-23) were used for bulk module poisoning. Weaponized interview templates (ShoeVista via tailwindcss-style-animate, StakingGame) deliver the chain. Follow-on payloads are BeaverTail loader and InvisibleFerret (tracked as DEV#POPPER RAT) and OmniStealer, which steal credentials, browser data and wallet information.
MITRE ATT&CK techniques used in TL-2026-3214
Credential Access
T1003.007 OS Credential Dumping: Proc Filesystem; T1528 Steal Application Access Token; T1552.001 Unsecured Credentials: Credentials In Files; T1552.004 Unsecured Credentials: Private Keys; T1555.003 Credentials from Password Stores: Credentials from Web Browsers
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Masquerading: Match Legitimate Resource Name or Location; T1070.006 Indicator Removal: Timestomp
Execution
T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.007 Command and Scripting Interpreter: JavaScript; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1568 Dynamic Resolution
Initial Access
T1078.004 Valid Accounts: Cloud Accounts; T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools; T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
Persistence
T1546 Event Triggered Execution
Resource Development
Affected products and versions in ChainDrop npm Worm and PolinRider DPRK-Linked Operation Use
- npm ecosystem — keyv, cacheable-request, flat-cache, cacheable, cache-manager and 400+ npm packages
Vulnerable versions: versions published during the 2026-08-04 ChainDrop compromise
Fixed in: maintainer-published clean releases - GitHub — GitHub Actions Runner (OIDC token and secret exposure in Runner.Worker memory)
Vulnerable versions: workflows executing compromised dependencies - Microsoft — Visual Studio Code workspace tasks (.vscode/tasks.json folderOpen abuse)
Vulnerable versions: workspaces opened without Workspace Trust review - Go / Packagist / npm / PyPI / Chrome Web Store — PolinRider-infected modules, packages and extensions (162 artifacts across 108 packages reported)
Vulnerable versions: infected versions per OpenSourceMalware/Socket reporting
Remediation for ChainDrop npm Worm and PolinRider DPRK-Linked Operation Use
Patches
- Pin to clean package versions published by maintainers after incident response; consult maintainer advisories for keyv, cacheable-request and affected packages
Immediate actions
- Identify installs of compromised keyv/cacheable ecosystem packages and any package with a setup.mjs preinstall hook; purge poisoned lockfiles, tarballs and CI image caches
- Revoke and rotate npm tokens, GitHub PATs, SSH keys, cloud IAM keys, Vault tokens, Kubernetes service-account tokens and any secrets exposed to CI runners
- Block C2 domains npm-cache.com, awqhnjewqjkl.icu, pypi-get.com, js-mirror.com and the PolinRider Vercel hosts via DNS/SNI (avoid IP blocking: Cloudflare shared IPs)
- Hunt for .vscode/tasks.json with runOn folderOpen, .claude/settings.json SessionStart hooks, .claude/setup.mjs, .vscode/setup.mjs and public repositories described 'Shai-Hulud: Here We Go Again'
- Audit repositories for git history rewrites, anti-dated commits, temp_auto_push.bat and JavaScript appended to config files or .woff2 files
Workarounds
- Treat VS Code workspace tasks and AI-assistant session hooks from untrusted repositories as untrusted (enable Workspace Trust, review .vscode and .claude directories before opening)
- Monitor Ethereum contract 0xE1f2395ee43e45A1556EC6438a88c31B83493103 for setStrings() calls
Longer-term hardening
- Use ephemeral CI runners and workload-bound credentials (OIDC with narrow audiences, SPIFFE, projected service-account tokens)
- Enforce egress filtering in CI/CD to private registries and known deployment targets
- Require 2FA on publish for all npm tokens and restrict trusted-publishing to protected workflows
- Plant canary credentials in ~/.aws/credentials, ~/.npmrc and .env files
- Disable lifecycle scripts by default in CI (npm ci --ignore-scripts) and monitor Ethereum RPC calls and blockchain API traffic from build hosts
Weaknesses (CWE) in ChainDrop npm Worm and PolinRider DPRK-Linked Operation Use
Timeline of ChainDrop npm Worm and PolinRider DPRK-Linked Operation Use
- Anti-dated malicious commits observed in 7span Packagist-related repositories, an early PolinRider indicator
- OpenSourceMalware publicly discloses PolinRider with 675 compromised repositories (352 owners)
- Expanded hunt finds 1,951 repositories across 1,047 owners; Cot%3t=shtP variant identified and merger with TasksJacker / Contagious Interview confirmed
- Earliest ChainDrop GitHub exfiltration repository created (Unit 42)
- ChainDrop C2 domains registered within 8 seconds of each other (13:40:28-13:40:36 UTC)
- Ethereum resolver contract 0xE1f2395ee43e45A1556EC6438a88c31B83493103 deployed; domain list narrowed to npm-cache.com minutes later
- Xpos587 GitHub account takeover and synchronized bulk modification of repositories / Go modules
- Cross-ecosystem spread confirmed: 162 malicious artifacts across 108 packages in npm, Go, Packagist
- keyv maintainer compromised; keyv monorepo backdoored and worm spreads to 400+ npm packages; C2 rotated to awqhnjewqjkl.icu via Ethereum transaction
- Unit 42 and Elastic Security Labs publish ChainDrop analyses
- GBHackers and Unit 42 report ChainDrop and PolinRider as blockchain-C2 cloud and CI/CD credential-theft campaigns
Sources cited for ChainDrop npm Worm and PolinRider DPRK-Linked Operation Use
- ChainDrop and PolinRider Use Blockchain C2 to Steal Cloud and CI/CD Credentials (GBHackers)
- ChainDrop: Inside a Self-Propagating npm Worm (Unit 42)
- Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages (Elastic Security Labs)
- Web3 Cloud Supply Chain Attacks (Unit 42)
- OpenSourceMalware PolinRider technical dossier
- PolinRider Jumps the Fence to Go, Packagist, npm, PyPI (OpenSourceMalware)
- North Korea Expands the Reach of PolinRider Supply Chain Attack Campaign (DevOps.com)
- North Korea-Linked Hackers Hide JavaScript Loaders in Open Source Repositories
- ChainDrop: The Keyv and Cacheable npm Supply Chain Attack (Integrity360)
- Shai-Hulud Returns: ChainDrop Worm Hits npm (OPSWAT)
- Hackers Compromise GitHub Maintainer Accounts to Publish PolinRider-Infected Package Versions (GBHackers)
Detection coverage for TL-2026-3214
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3214 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.