This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries.
1. @servicetitan/install (npm)
- Package: https://www.npmjs.com/package/@servicetitan/install
- Severity: high
- Affected versions: 38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5
- Downloads: 27414
- First seen: 4 August 2026 at 13:43 UTC
Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.
References: https://www.stepsecurity.io/blog/chaindrop-npm-worm
2. @servicetitan/tokens (npm)
- Package: https://www.npmjs.com/package/@servicetitan/tokens
- Severity: high
- Affected versions: 12.9.1, 12.9.2, 12.9.3, 12.9.4, 12.9.5, 12.9.6, 12.9.7
- Downloads: 22094
- First seen: 4 August 2026 at 13:44 UTC
Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.
References: https://www.stepsecurity.io/blog/chaindrop-npm-worm
3. @servicetitan/stylelint-config (npm)
- Package: https://www.npmjs.com/package/@servicetitan/stylelint-config
- Severity: high
- Affected versions: 38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
- Downloads: 20820
- First seen: 4 August 2026 at 13:44 UTC
Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.
References: https://www.stepsecurity.io/blog/chaindrop-npm-worm
4. @servicetitan/startup (npm)
- Package: https://www.npmjs.com/package/@servicetitan/startup
- Severity: high
- Affected versions: 38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
- Downloads: 20737
- First seen: 4 August 2026 at 13:44 UTC
Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.
References: https://www.stepsecurity.io/blog/chaindrop-npm-worm
5. @servicetitan/react-ioc (npm)
- Package: https://www.npmjs.com/package/@servicetitan/react-ioc
- Severity: high
- Affected versions: 38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
- Downloads: 19097
- First seen: 4 August 2026 at 13:44 UTC
Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.
References: https://www.stepsecurity.io/blog/chaindrop-npm-worm
6. qlik-modifiers (npm)
- Package: https://www.npmjs.com/package/qlik-modifiers
- Severity: high
- Affected versions: 0.10.1
- Downloads: 17401
- First seen: 4 August 2026 at 13:45 UTC
Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.
References: https://www.stepsecurity.io/blog/chaindrop-npm-worm
7. @servicetitan/startup-utils (npm)
- Package: https://www.npmjs.com/package/@servicetitan/startup-utils
- Severity: high
- Affected versions: 38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
- Downloads: 16612
- First seen: 4 August 2026 at 13:44 UTC
Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.
References: https://www.stepsecurity.io/blog/chaindrop-npm-worm
8. qlik-chart-modules (npm)
- Package: https://www.npmjs.com/package/qlik-chart-modules
- Severity: high
- Affected versions: 1.1.1
- Downloads: 16608
- First seen: 4 August 2026 at 13:45 UTC
Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.
References: https://www.stepsecurity.io/blog/chaindrop-npm-worm
9. @servicetitan/react-hooks (npm)
- Package: https://www.npmjs.com/package/@servicetitan/react-hooks
- Severity: high
- Affected versions: 7.7.1, 7.7.2, 7.7.3, 7.7.4, 7.7.5, 7.7.6, 7.7.7
- Downloads: 16349
- First seen: 4 August 2026 at 13:44 UTC
Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.
References: https://www.stepsecurity.io/blog/chaindrop-npm-worm
10. @servicetitan/log-service (npm)
- Package: https://www.npmjs.com/package/@servicetitan/log-service
- Severity: high
- Affected versions: 38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
- Downloads: 16072
- First seen: 4 August 2026 at 13:43 UTC
Compromised npm package infected via worm propagation in the Shai-Hulud/ChainDrop supply chain attack (Aug 4, 2026). Malicious versions contain obfuscated preinstall scripts (setup.mjs, math_init.js) that download the Bun runtime and execute a credential-harvesting payload targeting npm tokens, GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe keys, Slack tokens, SSH keys, and sensitive files. Exfiltrates encrypted data via Ethereum dead-drop C2.
References: https://www.stepsecurity.io/blog/chaindrop-npm-worm
Want help mitigating malicious packages before they reach your network?
ShieldedStack acts as a security proxy in front of npm, PyPI, NuGet, and Maven, helping teams detect and block malicious or risky packages before they reach developer machines or CI pipelines.
Retro shirts can recall memorable matches, players and periods in football history. For matchday clothing decisions, Atlético de Madrid jersey(camiseta del Atlético de Madrid) connects the selected design with its team identity. Small construction details can make a noticeable difference during long matchdays.
Learn more: https://shieldedstack.com
Credits for the core data goes to https://opensourcemalware.com