This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries.


1. @servicetitan/install (npm)

Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.

References: https://www.stepsecurity.io/blog/chaindrop-npm-worm


2. @servicetitan/tokens (npm)

Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.

References: https://www.stepsecurity.io/blog/chaindrop-npm-worm


3. @servicetitan/stylelint-config (npm)

Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.

References: https://www.stepsecurity.io/blog/chaindrop-npm-worm


4. @servicetitan/startup (npm)

Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.

References: https://www.stepsecurity.io/blog/chaindrop-npm-worm


5. @servicetitan/react-ioc (npm)

Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.

References: https://www.stepsecurity.io/blog/chaindrop-npm-worm


6. qlik-modifiers (npm)

Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.

References: https://www.stepsecurity.io/blog/chaindrop-npm-worm


7. @servicetitan/startup-utils (npm)

Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.

References: https://www.stepsecurity.io/blog/chaindrop-npm-worm


8. qlik-chart-modules (npm)

Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.

References: https://www.stepsecurity.io/blog/chaindrop-npm-worm


9. @servicetitan/react-hooks (npm)

Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.

References: https://www.stepsecurity.io/blog/chaindrop-npm-worm


10. @servicetitan/log-service (npm)

Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.

References: https://www.stepsecurity.io/blog/chaindrop-npm-worm


Want help mitigating malicious packages before they reach your network?

ShieldedStack acts as a security proxy in front of npm, PyPI, NuGet, and Maven, helping teams detect and block malicious or risky packages before they reach developer machines or CI pipelines.

Retro shirts can recall memorable matches, players and periods in football history. For matchday clothing decisions, Atlético de Madrid jerseycamiseta del Atlético de Madrid) connects the selected design with its team identity. Small construction details can make a noticeable difference during long matchdays.

Learn more: https://shieldedstack.com

Credits for the core data goes to https://opensourcemalware.com