What happened
On 2026-10-05 the maintainer-trusted @subql/common@5.8.3 shipped a postinstall credential stealer flagged by StepSecurity and SubQuery (issue #3047). Researchers tie it to the 'ChainDrop' self-propagating variant of the Shai-Hulud malware family (Elastic Security Labs reports hundreds of packages). The same week a malicious anthropic-sdk v0.1.0 appeared on PyPI (MAL-2026-17472), pulling its payload from a GitHub-hosted file and falling back to DNS exfiltration — a typosquat aimed squarely at AI SDK consumers. Reported in-window (Oct 5-7).
Why it matters
This is an active, self-propagating supply-chain campaign against developer tooling, including a typosquat on an AI SDK (anthropic-sdk). Because the worm spreads via GitHub Actions OIDC identity rather than stolen static secrets, standard rotate/rotate does not stop propagation — it compromises the exact CI/build environments that assemble and deploy AI agents, giving attackers the same secrets the agents use.
Attack vector
Postinstall/on-import payload (base64+XOR+gzip, disguised as a manifest-cache reader) harvests .npmrc, .env, AWS credentials, SSH keys, kubeconfig, and GitHub Actions runner memory, opens remote shell access, and exfiltrates to attacker infrastructure, with DNS exfiltration as a fallback.
Affected systems
npm ecosystem (e.g. @subql/common@5.8.3 published 2026-10-05, hundreds of packages per Elastic Security Labs); PyPI malicious anthropic-sdk v0.1.0 (MAL-2026-17472, 2026-10-04)
Mitigation
Treat public packages as untrusted-by-default; disable unnecessary install scripts; enable integrity-hash and provenance verification; egress-restrict CI runners and minimize/short-scope OIDC tokens; treat secrets on any machine that installed a bad version as burned. Remove any affected anthropic-sdk / @subql/common installs.