Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
Home»HACKING NEWS»The Shai Hulud malware has hit NPM as cryptocurrency libraries face a growing security crisis.
HACKING NEWS

The Shai Hulud malware has hit NPM as cryptocurrency libraries face a growing security crisis.

By Crypto FlexsNovember 24, 20254 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
The Shai Hulud malware has hit NPM as cryptocurrency libraries face a growing security crisis.
Share
Facebook Twitter LinkedIn Pinterest Email

  • The infection contains at least 10 major cryptographic packages linked to the ENS ecosystem.
  • A previous NPM attack in early September resulted in $50 million worth of cryptocurrency being stolen.
  • Researchers discovered more than 25,000 affected repositories during their investigation.

Shai Hulud A new NPM infection has raised concerns throughout the JavaScript community as malware continues to move through hundreds of software libraries.

Aikido Security confirmed that more than 400 NPM packages were compromised, including at least 10 widely used across the cryptocurrency ecosystem.

The scale of the problem places immediate pressure on developers, especially those using blockchain tools and applications, to assess risk.

The disclosure came on Monday, when Aikido Security released a detailed list of contaminated libraries after reviewing NPM for unusual behavior.

A separate post by researcher Charles Eriksen highlighted X’s list of infections, drawing attention to the key ENS packages involved in the incident.

The infection appears to be linked to active supply chain attacks that have been unfolding in recent weeks, adding momentum to a growing pattern of security incidents within JavaScript infrastructure.

The threat extends beyond previous NPM attacks.

The spike in infections followed a massive NPM breach in early September. The previous incident ended with attackers stealing $50 million worth of cryptocurrency, making it one of the largest supply chain incidents directly linked to digital asset theft.

According to Amazon Web Services, the attack led to the emergence of Shai Hulud within a week, which began to spread autonomously throughout the project.

The first incident in September directly targeted cryptocurrency assets, but Shai Hulud operates differently. It focuses on collecting credentials from any environment where an infected package is downloaded. If the wallet key exists, it is treated like any other secret and extracted.

This change in behavior has led to a wider range of new incidents.

Instead of targeting a single target, malware is integrated into developer workflows and moves through dependency chains, increasing the potential for accidental exposure in both cryptocurrency and non-cryptocurrency projects.

ENS packages are significantly affected

The latest review shows that the affected cryptocurrency packages are clearly focused around the Ethereum Name Service ecosystem. Several ENS-related libraries with tens of thousands of downloads each week appear in the corrupted list.

This includes content-hash, address-encoder, ensjs, ens-validation, ethereum-ens, and ens-contracts.

To support his findings, Eriksen shared a detailed X post describing the compromised ENS package. Soon after, Eriksen’s second X update expanded the spread of the infection, affecting additional repositories.

Each ENS package supports functionality used across wallet interfaces, blockchain applications, and tools to convert human-readable names into machine-readable format.

Their popularity means their impact can extend beyond direct maintenance personnel to downstream developers who rely on them for core operations.

A separate crypto library, crypto-addr-codec, was also identified among the compromised packages. Although not related to ENS, it is used for wallet-related processes and has high weekly traffic, making contamination another priority area for security review.

Increasing influence over non-crypto software

The proliferation is not limited to digital asset tools. Several non-crypto libraries were also affected, including packages related to workflow automation platform Zapier.

Some of these reports have weekly downloads well over 40,000, indicating that the malware has reached parts of the JavaScript ecosystem unrelated to blockchain activity.

Additional libraries highlighted in later posts demonstrate even higher level deployments. One package received close to 70,000 downloads per week.

Another record shows weekly traffic of more than 1.5 million, reflecting a much wider range than initial reports suggested.

The rapid expansion caught the attention of other security teams. Researchers at Wiz said they identified more than 25,000 affected repositories linked to about 350 users.

They also noted that in the early stages of their investigation, 1,000 new repositories were being added every 30 minutes.

This level of growth shows how quickly supply chain contamination can accelerate when packages are replicated through dependency networks.

Developers using NPM are advised to immediately perform a scan, validate their environment, and search for possible exposure.

Because dependency chains are interconnected across multiple industries, teams outside the cryptocurrency sector can also unknowingly integrate infected packages.


Share this article

Category

tag

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Real Finance partners with Anchorage Digital to expand RWA infrastructure

June 6, 2026

Videos and Podcasts | Vault12

May 27, 2026

ECHO Token Plunges After $76 Million Administrator Key Exploit Hits Protocol

May 25, 2026
Add A Comment

Comments are closed.

Recent Posts

Bybit Launches New Daily Treasure Hunt Season Featuring Football Match Tickets And XAUT Rewards

June 10, 2026

World Cup 2026 Prediction Markets Now Live On Whale.io With $90K In Prizes

June 10, 2026

Chris Jericho To Join And Co-Create Official Community Traits For Kokopi Koalas™ NFT Collection

June 9, 2026

Bancor reduced its stable fee to 0.001%. Can BNT bounce back?

June 9, 2026

Neura Closes Strategic Funding Round And Partnerships To Build Emotional AI With Persistent, User-Owned Memory

June 9, 2026

Phemex Kicks Off $7 Million Ultimate Championship, Bringing Trading Competition To Football Season

June 9, 2026

MEXC Prediction Markets Launches Combo To Enable Multi-Event Combination Trading

June 9, 2026

ZIGChain expands on-chain access by integrating Ondo tokenized stocks and ETFs.

June 8, 2026

Bitmine Immersion Technologies (BMNR) Announces ETH Holdings Reach 5.54 Million Tokens, And Total Crypto And Total Cash Holdings Of $9.6 Billion

June 8, 2026

MapleStory Universe Opens MSU Space And Launches Global Game Jam Competition As Part Of MSU 2.0 Expansion

June 8, 2026

Why is UK Financial Ltd’s trillion-dollar ERC-3643 conversion attracting major platforms?

June 7, 2026

Crypto Flexs is a Professional Cryptocurrency News Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of Cryptocurrency. We hope you enjoy our Cryptocurrency News as much as we enjoy offering them to you.

Contact Us : Partner(@)Cryptoflexs.com

Top Insights

Bybit Launches New Daily Treasure Hunt Season Featuring Football Match Tickets And XAUT Rewards

June 10, 2026

World Cup 2026 Prediction Markets Now Live On Whale.io With $90K In Prizes

June 10, 2026

Chris Jericho To Join And Co-Create Official Community Traits For Kokopi Koalas™ NFT Collection

June 9, 2026
Most Popular

Cryptorefills Announces Launch of Innovative Loyalty Program “The 7 Deadly Sins” NFT Gift Card Collection

June 19, 2024

Bitcoin’s ‘Make or Break’ Moment Depends on $46,000 BTC Price Support – Research

September 13, 2024

Bitcoin Investor requires a rally for $ 118K

May 29, 2025
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
© 2026 Crypto Flexs

Type above and press Enter to search. Press Esc to cancel.