Major Supply-Chain Attack Targets Crypto-Related Software Packages A significant JavaScript supply-chain attack has compromised over 400 software packages, including at least 10 heavily used within the cryptocurrency ecosystem. The breach was uncovered by cybersecurity firm Aikido Security, highlighting the evolving threat landscape faced by developers and users alike. In a detailed blog post, researcher Charlie [...]Major Supply-Chain Attack Targets Crypto-Related Software Packages A significant JavaScript supply-chain attack has compromised over 400 software packages, including at least 10 heavily used within the cryptocurrency ecosystem. The breach was uncovered by cybersecurity firm Aikido Security, highlighting the evolving threat landscape faced by developers and users alike. In a detailed blog post, researcher Charlie [...]

New NPM Supply Chain Hack Threatens ENS and Cryptocurrency Security

New Npm Supply Chain Hack Threatens Ens And Cryptocurrency Security

A significant JavaScript supply-chain attack has compromised over 400 software packages, including at least 10 heavily used within the cryptocurrency ecosystem. The breach was uncovered by cybersecurity firm Aikido Security, highlighting the evolving threat landscape faced by developers and users alike.

In a detailed blog post, researcher Charlie Eriksen outlined the scope of the infection, identifying packages infected with the “Shai Hulud” malware—an autonomous, self-replicating strain designed to spread across developer environments. Eriksen confirmed the validity of each detection to prevent false positives. Many of these packages are responsible for critical functions, with some receiving tens of thousands of weekly downloads, emphasizing the widespread potential impact.

Of particular concern are the affected packages associated with the Ethereum Name Service (ENS), which facilitate human-readable blockchain addresses. Notable among these are ENS’s content-hash, with nearly 36,000 weekly downloads, and address-encoder, with over 37,500 weekly downloads. Other ENS packages, such as ensjs, ens-validation, ethereum-ens, and ens-contracts, are also compromised. A separate package, crypto-addr-codec, unrelated to ENS, with nearly 35,000 weekly downloads, was also affected.

Source: Charlie Eriksen

This incident is part of a broader trend of supply-chain attacks. In September, the largest NPM attack to date resulted in approximately $50 million stolen from crypto assets. Amazon Web Services highlighted that this incident was followed by the spread of the Shai-Hulud worm, which replicated itself across environments post-initial breach.

Unlike previous targeted thefts, Shai Hulud primarily acts as a credential-stealer, spreading autonomously and harvesting wallet keys and other secrets stored within infected environments. This capability poses a significant threat to the security of blockchain assets if such secrets are stored insecurely.

Scope of the Affected Packages

Among the impacted packages, at least 10 are directly related to cryptocurrency functions, predominantly tied to the ENS ecosystem. Packages such as content-hash, with nearly 36,000 weekly downloads, and address-encoder, exceeding 37,500 downloads, are critical components used by developers to handle address and name resolution. Other key packages affected include ensjs, ens-validation, ethereum-ens, and ens-contracts.

Beyond crypto, several non-crypto packages are compromised, including popular tools from Zapier, like @zapier/secret-scrubber, with over 40,000 weekly downloads. Eriksen warned that affected packages with high download volumes, some approaching 70,000 weekly downloads, underscore the widespread reach of the malware.

Researchers from Wiz estimate that over 25,000 repositories across hundreds of users have been impacted, with new compromised repositories added every 30 minutes. The cybersecurity community urges immediate investigations and remediation efforts for any environment utilizing npm packages.

This article was originally published as New NPM Supply Chain Hack Threatens ENS and Cryptocurrency Security on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.

Market Opportunity
ENS Logo
ENS Price(ENS)
$10.317
$10.317$10.317
+0.08%
USD
ENS (ENS) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

The post Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be appeared on BitcoinEthereumNews.com. Jordan Love and the Green Bay Packers are off to a 2-0 start. Getty Images The Green Bay Packers are, once again, one of the NFL’s better teams. The Cleveland Browns are, once again, one of the league’s doormats. It’s why unbeaten Green Bay (2-0) is a 8-point favorite at winless Cleveland (0-2) Sunday according to betmgm.com. The money line is also Green Bay -500. Most expect this to be a Packers’ rout, and it very well could be. But Green Bay knows taking anyone in this league for granted can prove costly. “I think if you look at their roster, the paper, who they have on that team, what they can do, they got a lot of talent and things can turn around quickly for them,” Packers safety Xavier McKinney said. “We just got to kind of keep that in mind and know we not just walking into something and they just going to lay down. That’s not what they going to do.” The Browns certainly haven’t laid down on defense. Far from. Cleveland is allowing an NFL-best 191.5 yards per game. The Browns gave up 141 yards to Cincinnati in Week 1, including just seven in the second half, but still lost, 17-16. Cleveland has given up an NFL-best 45.5 rushing yards per game and just 2.1 rushing yards per attempt. “The biggest thing is our defensive line is much, much improved over last year and I think we’ve got back to our personality,” defensive coordinator Jim Schwartz said recently. “When we play our best, our D-line leads us there as our engine.” The Browns rank third in the league in passing defense, allowing just 146.0 yards per game. Cleveland has also gone 30 straight games without allowing a 300-yard passer, the longest active streak in the NFL.…
Share
BitcoinEthereumNews2025/09/18 00:41
Academic Publishing and Fairness: A Game-Theoretic Model of Peer-Review Bias

Academic Publishing and Fairness: A Game-Theoretic Model of Peer-Review Bias

Exploring how biases in the peer-review system impact researchers' choices, showing how principles of fairness relate to the production of scientific knowledge based on topic importance and hardness.
Share
Hackernoon2025/09/17 23:15
The Role of Reference Points in Achieving Equilibrium Efficiency in Fair and Socially Just Economies

The Role of Reference Points in Achieving Equilibrium Efficiency in Fair and Socially Just Economies

This article explores how a simple change in the reference point can achieve a Pareto-efficient equilibrium in both free and fair economies and those with social justice.
Share
Hackernoon2025/09/17 22:30