ChainDrop: Inside a Self-Propagating npm Worm

LowUnit 42 · Unit 42·

Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42 .

We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what NexaPulse adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.

At a glance

Severity
Lowfrom category and source signals; no CVSS referenced
Exploitation
No vulnerabilities referenced
Vulnerabilities
None referenced
Vendors & products
GitHub
Threat actors & malware
None named
Industries
Not industry-specific
Coverage
1 outlet· first seen 2026-08-06 22:26 UTC
Priority
22/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.

Coverage

One outlet has carried this so far.

  1. Unit 42Established SourceFirst reported

    2026-08-06 22:26 UTC

Related stories