YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0048

Incident record

ChainDrop npm worm plants a Claude Code startup hook to run before a developer types a prompt

Severity
Critical
Status
In the wild
Type
Poisoning
Target
npm packages and developers using Claude Code and VS Code
Actor
criminal

What happened

Microsoft and Pillar Security separately reported a self-propagating npm supply-chain worm named ChainDrop. Microsoft counted more than 400 poisoned packages across multiple unrelated publishers; Aikido put it at 444 packages a day later, carrying over 2 billion combined monthly installs, and StepSecurity timed the run at under four hours, from the first malicious publish at 09:35 UTC on 4 August 2026 to 13:20 UTC. Pillar found the worm specifically targeted AI coding tools, planting a Claude Code SessionStart hook and a matching VS Code folderOpen task so its credential-stealing payload ran the moment a developer opened a repository, before any prompt was typed.

The campaign began with the compromise of a maintainer account for the widely used keyv package, and keyv 6.0.0 was the first carrier. It spread by stealing npm publishing tokens, pushing malicious patch releases across every package each stolen publisher controlled. The payload harvested npm, GitHub, cloud, Kubernetes and Vault credentials and exfiltrated them to a public GitHub repository. Version counts differ by vendor: Aikido logged 1,381 affected versions, StepSecurity 2,212. Elastic Security Labs puts the combined monthly downloads lower, above 1.3 billion, with keyv alone above 600 million in the preceding month. StepSecurity says npm began removing malicious versions about two hours in, and Microsoft said cleanup was continuing as the worm kept propagating.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026