More than 2,200 malicious versions of 440 packages were published to the NPM registry as part of a fresh Mini Shai-Hulud supply chain attack.

Dubbed ChainDrop, the campaign started with 11 malware carriers in the keyv and cacheable namespaces, after their maintainer’s GitHub account was compromised.

Combined, the infected packages have over 500 million weekly downloads. They are widely used across the ecosystem and their poisoning led to 433 additional packages being infected.

Similar to previous Mini Shai-Hulud attacks, the infected packages executed malicious code during installation, dropping an information stealer with self-propagation functionality.

On the infected machines, the malware targets all the secrets it can find, encrypts them, and then exfiltrates the data either to a dynamic HTTPS endpoint or to attacker-created public GitHub repositories that have the ‘Shai-Hulud: Here We Go Again’ description.