BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Massive Shai Hulud JavaScript Attack Hits 400+ Packages, Crypto APIs

  • A widespread JavaScript supply-chain attack has infected over 400 npm packages with the “Shai Hulud” Malware.
  • At least 10 compromised packages are widely used in the cryptocurrency ecosystem, notably those linked to the Ethereum Name Service (ENS).
  • Shai Hulud is a credential-stealing malware that spreads autonomously across developer infrastructures.
  • Popular non-crypto packages, including some from Zapier, are also affected.
  • Cybersecurity firms highlight the urgent need for investigation and remediation for environments using npm.

A new JavaScript supply-chain attack has compromised more than 400 software packages, including at least 10 heavily used in the cryptocurrency sector. The ongoing infection, driven by the “Shai Hulud” malware, was revealed on Monday by researcher Charlie Eriksen from cybersecurity firm Aikido Security, who confirmed each case to avoid false positives. Several affected packages are integral to the Ethereum Name Service (ENS), a service providing human-readable blockchain addresses.

- Advertisement -

The “Shai Hulud” malware is a self-replicating worm that spreads automatically within npm libraries, targeting developer environments to steal credentials, including wallet keys if present. This malicious activity follows an earlier npm attack in early September that resulted in the theft of about $50 million in cryptocurrency. According to Amazon Web Services, Shai Hulud emerged soon after, representing a shift toward general-purpose credential theft rather than direct asset theft, as noted in their security blog.

Among the crypto packages infected are ENS-related ones such as content-hash with nearly 36,000 weekly downloads and 91 dependent packages, address-encoder with over 37,500 weekly downloads, ensjs, ens-validation, ethereum-ens, and ens-contracts. An additional crypto package, crypto-addr-codec, with around 35,000 weekly downloads, was also compromised. Eriksen warned the ENS team about these vulnerabilities on his X post.

Non-cryptocurrency packages hit include some offered by Zapier, with downloads up to around 40,000 weekly. Other infected packages mentioned by Eriksen include ones with close to 70,000 weekly downloads and a package called posthog-node, which sees over 1.5 million downloads weekly. Cybersecurity firm Wiz reported identifying more than 25,000 affected repositories involving roughly 350 unique users and noted that about 1,000 new infected repositories are added every 30 minutes. Wiz urges immediate action to investigate and remediate npm environments, as detailed in their blog post.

“The scope of this new Shai Hulud attack is frankly massive; we’re still working through the queue to confirm it all,” Eriksen wrote on X. “It’ll make the previous attack look like nothing.”

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

SanDisk Stock Hits $1,600, Bernstein Predicts $3,000

SanDisk (NASDAQ: SNDK) stock opened Friday at $1,600, surging 480% year-to-date amid the AI...

Poll: 63% of Americans say Trump crypto profits inappropriate

A new Reuters/Ipsos poll found 63% of respondents consider it inappropriate for Trump and...

Coldcard adds user entropy to seed generation after $112M exploit

Coinkite released firmware 5.6.1 for Coldcard Mk4/Mk5 and 1.5.1Q for Coldcard Q, requiring user-supplied...

GitLab Flaw Actively Exploited After Disclosure

A critical GitLab vulnerability (CVE-2026-19478, CVSS 9.4) enables unauthenticated attackers to modify or delete...

PEPE Surges 25% Weekly, Outperforms Bitcoin and Ethereum

PEPE surged 14.2% in 24 hours and over 25% in the past week, outperforming...

Must Read

5 Best Crypto Jobs Sites To Land Your Next Six Figure Job

The cryptocurrency and blockchain job market has exploded. With new blockchain start-ups and projects being founded at a blistering pace, the demand for workers...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading