Developer credentials targeted via ChainDrop malware and the PolinRider campaign
09 Oct 2026
Cybersecurity researchers have reported software supply chain campaigns involving ChainDrop and PolinRider that target developer environments to steal credentials and maintain access to enterprise development workflows.
Through our blog, we will understand what the ChainDrop and PolinRider threats are about, how they impact organizations, and what they can do to defend against them.
About the threat
|
Threat names |
Threat type |
Affected environments |
Primary targets |
Key techniques |
|
|
|
|
|
About ChainDrop
ChainDrop is a self-propagating npm supply-chain worm that was identified in 2026. It is a variant of the Shai-Hulud malware family and has affected more than 300 npm packages. It can collect npm and GitHub tokens, SSH keys, cloud credentials, and temporary credentials from running CI/CD processes.
About PolinRider
PoinRider is a campaign involving software supply chain attacks targeted at developer ecosystems through the compromise of accounts and repositories for credential theft and malware distribution.
The campaign has been observed across npm, Go moduls, and Packagist. It involves stealing of developer credentials, cloud session tokens, and environment secrets.

How does it impact organizations?
Via ChainDrop and PolinRider, attackers can
- Steal cloud credentials, access tokens, and developer secrets.
- Cause a compromise of npm and GitHub accounts to access repositories and publish malicious packages.
- Gain unauthorized access to CI/CD pipelines and cloud environments.
- Spread malware through compromised software packages and developer workflows.
- Maintain execution through malicious developer-tool configurations
- Evade conventional domain-blocking defenses using blockchain based C2 resolution
SharkStriker’s recommendations
- Audit dependencies and lockfiles for affected or suspicious package versions.
- Remove confirmed malicious packages and investigate potentially compromised developer workstations and CI/CD runners.
- Revoke and rotate potentially exposed npm, GitHub, cloud, SSH, and automation credentials.
- Review repository history and package publishing logs for unauthorized changes.
- Inspect IDE workspace configurations and unexpected lifecycle scripts.
- Monitor outbound blockchain RPC traffic where it is not required for business operations.
- Review cloud audit logs for suspicious use of developer or CI/CD identities.
- Strengthen package controls, dependency review, and secrets management across development pipelines.
SharkStriker’s actions
- Threat intelligence reviewed using the supplied research sources.
- ChainDrop and PolinRider attack techniques assessed for detection opportunities.
- Credential theft, malicious dependency execution, and blockchain-based C2 identified as priority monitoring areas.
- Threat hunting recommended across developer endpoints, source repositories, CI/CD runners, and cloud audit logs.