{
  "schema_version": "1.6.0",
  "id": "CLR-2026-3042",
  "modified": "2026-08-05T15:30:00Z",
  "published": "2026-08-05T15:30:00Z",
  "summary": "Shai-Hulud / ChainDrop — self-propagating npm worm across 665 package versions",
  "details": "codelake Research corpus verified against Wiz Research IOC list — 439/443 unique package names (99% name coverage), 665 flagged versions, 100% detection precision on the ingested subset.",
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "Shai-Hulud / ChainDrop npm worm"
      },
      "versions": [
        "multiple (see IOC list)"
      ]
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://research.codelake.dev/advisories/clr-2026-3042-shai-hulud"
    },
    {
      "type": "WEB",
      "url": "https://github.com/wiz-sec-public/wiz-research-iocs/blob/main/reports/keyv-packages.csv"
    }
  ],
  "credits": [
    {
      "name": "Sascha Klein, codelake Research",
      "type": "FINDER",
      "contact": [
        "https://research.codelake.dev"
      ]
    }
  ],
  "database_specific": {
    "caseId": "CLR-2026-3042",
    "kind": "malware",
    "class": "Self-propagating supply-chain worm",
    "severity": "Critical",
    "status": "Public",
    "iocs": {
      "ips": [],
      "hashes": [],
      "indicators": [
        "setup.mjs — preinstall entrypoint; downloads bun, invokes payload",
        "math_init.js — ~728 KB obfuscated infostealer payload",
        "Math_Symbol.js — variant name of the same payload",
        "router_runtime.js — additional dropper variant",
        "Shai-Hulud: Here We Go Again — attacker signature (GitHub commit tag)",
        "Thebeautifulmarchoftime — attacker marker string in payload",
        "IfYouBlockThisAPIKeyItWillCrashTheLiveProductionServersOfAllThirdPartyClients — attacker marker string",
        "github.com — C2; exfiltration commits tagged Shai-Hulud: Here We Go Again; 821 tagged repos identified by Wiz"
      ]
    }
  }
}