MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Security Shock: NPM Supply‑Chain Attack Targets Major Crypto Ecosystem Libraries – Crypto Economy
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$78,585.003.97%
  • ethereumEthereum(ETH)$2,394.503.51%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$1.441.16%
  • binancecoinBNB(BNB)$642.642.12%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$87.312.43%
  • tronTRON(TRX)$0.329184-1.88%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-1.19%
  • dogecoinDogecoin(DOGE)$0.0964842.00%
Ethereum

Security Shock: NPM Supply‑Chain Attack Targets Major Crypto Ecosystem Libraries – Crypto Economy

Last updated: November 24, 2025 9:05 pm
Published: 5 months ago
Share

Non-crypto packages are also affected, with experts urging immediate investigation and remediation to prevent further spread.

A major JavaScript supply-chain attack has hit the crypto ecosystem, compromising hundreds of NPM packages, including at least ten widely used in Ethereum Name Service (ENS) projects. Cybersecurity researcher Charlie Eriksen from Aikido Security confirmed that these packages were infected with Shai Hulud malware, a self-replicating worm capable of stealing credentials and spreading autonomously. The malware poses a significant risk to any environment where affected libraries are installed.

Among the infected packages, ENS-related libraries are most affected. The content-hash package alone, which has nearly 36,000 weekly downloads and 91 dependent packages, is compromised, alongside address-encoder, ensjs, ens-validation, ethereum-ens, and ens-contracts. An unrelated crypto package, crypto-addr-codec, with nearly 35,000 downloads per week, was also impacted. These infections threaten the integrity of tools relied on by developers across the crypto ecosystem, potentially exposing sensitive environment secrets if wallet keys or private credentials are present.

Non-crypto packages were also affected. Automation platform Zapier and other widely used libraries with tens of thousands of weekly downloads were compromised, with some packages seeing over 1.5 million weekly downloads. Eriksen described the scale of the attack as “massive”, warning that the worm continuously spreads across repositories, making detection and remediation urgent.

Shai Hulud differs from previous attacks, which targeted cryptocurrency directly to steal assets. Instead, it is a general-purpose credential-stealing malware, capable of harvesting secrets, replicating itself, and even exposing private repositories. Crypto forensics expert Slava Demchuk noted that while there is no evidence of wallet keys being stolen yet, any sensitive secrets in infected environments should be considered exposed, raising alarms about potential downstream risks.

Cybersecurity firm Wiz reported over 25,000 affected repositories, with 1,000 new repositories being added every 30 minutes. The firms recommend immediate investigation and remediation for any developer using npm packages to prevent further compromise. The attack highlights vulnerabilities in the supply-chain model and underscores the need for stricter security protocols in open-source ecosystems.

Read more on Crypto Economy

This news is powered by Crypto Economy Crypto Economy

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Crypto Price Prediction Today 4 August – XRP, Shiba Inu, Pepe | Analysis Ripple | CryptoRank.io
Ethereum’s $11B staking withdrawal delays ignite concerns over systemic vulnerabilities
MAGACOIN FINANCE Reddit Buzz: Why Analysts See 50x ROI Potential in 2025
Ethereum As The Default Crypto Backbone: The Real Reason Behind Tom Lee’s Pick | Bitcoin Ethereum | CryptoRank.io
Top 6 Coins Poised for a 100x Crypto Breakout: Apeing, Solana, and XRP Take Center Stage

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Key Misconception on XRP Ledger Smart Contracts Debunked by XRPL Validator – Crypto Economy
Next Article Weak Sentiment In Crypto Markets
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d