3 outlets·3 reports
The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one

ThinkingNews Desk · how this was written
A worm dubbed ChainDrop, based on the Shai-Hulud code, has infiltrated more than 1,300 npm packages, including well-known modules such as Keyv, Cacheable and flat-cache. The malware disguises itself as a legitimate package, passing security checks and appearing trustworthy, which allowed it to spread widely across the npm ecosystem.
Written from all 3 reports below, not from any single one.
How it was reported
- TechMeme·Researchers: ChainDrop, a Shai-Hulud-based worm, has compromised 1,300+ npm packages, like Keyv, Cacheable, and flat-cache, with a combined 2B monthly downloads (Bill Toulas/BleepingComputer)
- The Next Web·A worm tore through npm by making the malware look perfectly legitimate
- VentureBeat·The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one
Related stories
- Protect your enterprise now from the Shai-Hulud worm and npm vulnerability in 6 actionable steps3 outlets
- Kaspersky says Daemon Tools, a widely used app for mounting disk images, has been backdoored in a monthlong compromise that has pushed malicious updates (Dan Goodin/Ars Technica)3 outlets
- Researchers show how AI-powered worms could wreak havoc on the internet3 outlets
- Meta claims its own AI also hacked into a third-party service during testing3 outlets