BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Massive Shai Hulud JavaScript Attack Hits 400+ Packages, Crypto APIs

  • A widespread JavaScript supply-chain attack has infected over 400 npm packages with the “Shai Hulud” Malware.
  • At least 10 compromised packages are widely used in the cryptocurrency ecosystem, notably those linked to the Ethereum Name Service (ENS).
  • Shai Hulud is a credential-stealing malware that spreads autonomously across developer infrastructures.
  • Popular non-crypto packages, including some from Zapier, are also affected.
  • Cybersecurity firms highlight the urgent need for investigation and remediation for environments using npm.

A new JavaScript supply-chain attack has compromised more than 400 software packages, including at least 10 heavily used in the cryptocurrency sector. The ongoing infection, driven by the “Shai Hulud” malware, was revealed on Monday by researcher Charlie Eriksen from cybersecurity firm Aikido Security, who confirmed each case to avoid false positives. Several affected packages are integral to the Ethereum Name Service (ENS), a service providing human-readable blockchain addresses.

- Advertisement -

The “Shai Hulud” malware is a self-replicating worm that spreads automatically within npm libraries, targeting developer environments to steal credentials, including wallet keys if present. This malicious activity follows an earlier npm attack in early September that resulted in the theft of about $50 million in cryptocurrency. According to Amazon Web Services, Shai Hulud emerged soon after, representing a shift toward general-purpose credential theft rather than direct asset theft, as noted in their security blog.

Among the crypto packages infected are ENS-related ones such as content-hash with nearly 36,000 weekly downloads and 91 dependent packages, address-encoder with over 37,500 weekly downloads, ensjs, ens-validation, ethereum-ens, and ens-contracts. An additional crypto package, crypto-addr-codec, with around 35,000 weekly downloads, was also compromised. Eriksen warned the ENS team about these vulnerabilities on his X post.

Non-cryptocurrency packages hit include some offered by Zapier, with downloads up to around 40,000 weekly. Other infected packages mentioned by Eriksen include ones with close to 70,000 weekly downloads and a package called posthog-node, which sees over 1.5 million downloads weekly. Cybersecurity firm Wiz reported identifying more than 25,000 affected repositories involving roughly 350 unique users and noted that about 1,000 new infected repositories are added every 30 minutes. Wiz urges immediate action to investigate and remediate npm environments, as detailed in their blog post.

“The scope of this new Shai Hulud attack is frankly massive; we’re still working through the queue to confirm it all,” Eriksen wrote on X. “It’ll make the previous attack look like nothing.”

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Crypto PAC drops $1.75M on Texas GOP Senate candidate Paxton

The crypto-aligned Fellowship PAC spent over $3 million on political advertising this week, with...

Anthropic Hits $1 Trillion Valuation on Secondary Markets

Secondary market trades now value AI firm Anthropic at approximately $1 trillion, surpassing OpenAI's...

Lightning Network’s Mexican Standoff Paralyzes BTC Routing

Bitcoin’s Lightning Network is locked in a recurring liquidity "Mexican standoff" where routing nodes...

120 Crypto Firms Urge US Senate to Pass Market Structure Bill

More than 120 crypto industry entities have urged US Senate Banking Committee leaders to...

Bitwarden CLI Compromised by Checkmarx Supply Chain Attack

The official Bitwarden CLI package on npm was compromised, distributing a malicious version that...

Must Read

Top 10 BEST Crypto Trading Books for New Traders

If you're thinking of diving into the crypto trading space, acquiring solid knowledge isn't just recommended - it's essential to protect your investment.Learning...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading