Developer credentials targeted via ChainDrop malware and the PolinRider campaign

09 Oct 2026

Cybersecurity researchers have reported software supply chain campaigns involving ChainDrop and PolinRider that target developer environments to steal credentials and maintain access to enterprise development workflows.

 

Through our blog, we will understand what the ChainDrop and PolinRider threats are about, how they impact organizations, and what they can do to defend against them.

About the threat

Threat names 

Threat type 

Affected environments 

Primary targets 

Key techniques 

  • ChainDrop 
  • PolinRider 

 

  • Software Supply Chain Compromise 
  • Credential Theft 

 

  • npm 
  • Go modules 
  • Packagist, and developer environments  

 

  • Developer workstations 
  • CI/CD pipelines 
  • Cloud environments 

 

  • Malicious package releases 
  • Credential harvesting, persistence 
  • Blockchain-based command-and-control (C2) 

 

About ChainDrop

ChainDrop is a self-propagating npm supply-chain worm that was identified in 2026. It is a variant of the Shai-Hulud malware family and has affected more than 300 npm packages. It can collect npm and GitHub tokens, SSH keys, cloud credentials, and temporary credentials from running CI/CD processes.

 

About PolinRider

PoinRider is a campaign involving software supply chain attacks targeted at developer ecosystems through the compromise of accounts and repositories for credential theft and malware distribution.

 

The campaign has been observed across npm, Go moduls, and Packagist. It involves stealing of developer credentials, cloud session tokens, and environment secrets.

How ChainDrop Malware Works

How does it impact organizations?

Via ChainDrop and PolinRider, attackers can

 

  • Steal cloud credentials, access tokens, and developer secrets.
  • Cause a compromise of npm and GitHub accounts to access repositories and publish malicious packages.
  • Gain unauthorized access to CI/CD pipelines and cloud environments.
  • Spread malware through compromised software packages and developer workflows.
  • Maintain execution through malicious developer-tool configurations
  • Evade conventional domain-blocking defenses using blockchain based C2 resolution

SharkStriker’s recommendations

  • Audit dependencies and lockfiles for affected or suspicious package versions.
  • Remove confirmed malicious packages and investigate potentially compromised developer workstations and CI/CD runners.
  • Revoke and rotate potentially exposed npm, GitHub, cloud, SSH, and automation credentials.
  • Review repository history and package publishing logs for unauthorized changes.
  • Inspect IDE workspace configurations and unexpected lifecycle scripts.
  • Monitor outbound blockchain RPC traffic where it is not required for business operations.
  • Review cloud audit logs for suspicious use of developer or CI/CD identities.
  • Strengthen package controls, dependency review, and secrets management across development pipelines.

SharkStriker’s actions

  • Threat intelligence reviewed using the supplied research sources.
  • ChainDrop and PolinRider attack techniques assessed for detection opportunities.
  • Credential theft, malicious dependency execution, and blockchain-based C2 identified as priority monitoring areas.
  • Threat hunting recommended across developer endpoints, source repositories, CI/CD runners, and cloud audit logs.

Get in Touch With us

We have explored what risk tolerance and risk appetite are and how important they are together in helping businesses align cybersecurity with their business goals. It can help CISOs, and C-suite make informed investment decisions for cybersecurity.

LEARN MORE