Close Menu
    What's Hot

    Oscars 2026: Photos and Details You Might Have Missed

    March 16, 2026

    Current energy price spikes are disinflationary – Ironsides Macroeconomics

    March 16, 2026

    Meta Might Be Creating the New Blueprint for an AI-First Company

    March 16, 2026
    Facebook X (Twitter) Instagram
    Hot Paths
    • Home
    • News
    • Politics
    • Money
    • Personal Finance
    • Business
    • Economy
    • Investing
    • Markets
      • Stocks
      • Futures & Commodities
      • Crypto
      • Forex
    • Technology
    Facebook X (Twitter) Instagram
    Hot Paths
    Home»Markets»Crypto»Massive NPM Supply-Chain Attack Targets ENS-Linked Libraries in Shai Hulud Breach
    Crypto

    Massive NPM Supply-Chain Attack Targets ENS-Linked Libraries in Shai Hulud Breach

    Press RoomBy Press RoomNovember 24, 2025No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A massive JavaScript-based Node Package Manager (npm) supply-chain attack has infiltrated code libraries connected to the Ethereum Name Service (ENS) and hundreds of older software packages, with over 10 widely used across the crypto ecosystem, according to cybersecurity firm Aikido Security.

    Charlie Eriksen, a malware researcher at the security firm, disclosed that the supply-chain malware known as “Shai-Hulud: The Second Coming” has infected hundreds of packages and more than 25,000 GitHub repositories.

    According to the findings, threat actors have embedded this malicious code into over 490 npm packages with more than 132 million monthly downloads, including prominent ones from ENS, Zapier, AsyncAPI, Browserbase, and Postman.

    Shai-Hulud 2.0: A new wave of npm supply-chain attacks targeting major packages (Zapier, ENS, PostHog, Postman & more) is ongoing.

    Attackers inject malicious code into published versions, triggering during pre-install to gain code execution and exfiltrate environment vars,…

    — Charles Guillemet (@P3b7_) November 24, 2025

    “If a developer installs one of these bad packages, the malware quietly runs during installation, before anything even finishes installing,” Eriksen said.

    How the Shai-Hulud Supply-Chain Malware Works

    As described by Akido security, the Shai-Hulud malware gains access to the developer’s machine or cloud environment during installation.

    It then deploys an automated tool called TruffleHog to scan for sensitive data, including passwords, API keys, cloud tokens, and GitHub or NPM credentials.

    Any discovered information is then uploaded to a public GitHub repository titled “Shai-Hulud: The Second Coming.”

    If the stolen credentials include access to code repositories or package registries, attackers can leverage them to breach additional accounts and distribute more malicious packages, allowing the attack to propagate further.

    Evolution from September’s Attack

    The initial Shai-Hulud breach occurred in early September, marking the largest npm attack on record at the time, with hackers stealing $50 million in cryptocurrency.

    Ledger hardware wallet noted that this first attack was followed by the Shai Hulud worm spreading autonomously a week later.

    However, the infiltration method for this second wave appears substantially different.

    The “Shai-Hulud: The Second Coming” first installs Bun via the file setup_bun.js, then uses it to execute bun_environment.js, which contains the actual malicious code.

    Massive NPM Supply-Chain Attack Targets ENS-Linked Libraries in Shai Hulud Breach
    Source: Aikido Blog

    It creates randomly named repositories with stolen data rather than using hardcoded names, and can infect up to 100 npm packages compared to 20 in the previous attack.

    Self-Propagating Malware Exposes Blind Spot in NPM Packages

    Charles Guillemet, Chief Technology Officer at crypto hardware wallet Ledger, alerted the community that the malware also targets API keys, Git credentials, and CI/CD secrets, then quietly exfiltrates everything.

    “If you use affected packages: PLEASE check this carefully: consider your credentials and secrets compromised, audit your infrastructure, and rotate your credentials,” he cautioned.

    🚨 Ledger CTO warned to "AVOID ON-CHAIN TRANSACTIONS" after a JavaScript supply chain attack compromised NPM packages with over 1B downloads. #JavaScript #crypto https://t.co/JjT23tk8CG

    — Cryptonews.com (@cryptonews) September 8, 2025

    He urged that anyone without close CI monitoring might consider shutting down their systems.

    Florian Roth, Head of Research at Nextron Systems, also added that it’s becoming increasingly easy for threat actors to inject malware into sensitive systems due to blind spots in NPM packages.

    According to his assessment, the industry previously fought malware at the OS level, but now the same behavior occurs one layer up, inside the software ecosystems people trust every day.

    We used to fight worms on the OS level. Slammer, Blaster, Conficker.. all that stuff

    Now we get the same behaviour one layer up – inside the software ecosystems we trust every day

    NPM tokens, transitive deps, weak account hygiene, zero visibility… and suddenly a… pic.twitter.com/6aSNEL4c32

    — Florian Roth ⚡ (@cyb3rops) November 24, 2025

    “NPM tokens, transitive deps, weak account hygiene, zero visibility… and suddenly a self-propagating worm runs through the supply chain like it’s 2003 again.”

    He concluded that the recent Shai Hulud breach reveals the real blind spot is in package ecosystems acting as execution surfaces.

    “Nobody monitors them, nobody hardens them, and attackers don’t even need an exploit to make them go wild,” he said.

    JP Richardson, CEO of Exodus, the first public company in the U.S. to tokenize stocks on the blockchain, also questioned Microsoft for making it “easy” for threat actors to propagate malware.

    In a November 24 post, Richardson said, “What I don’t understand [is] why Microsoft (npm owner) is not moving fast enough to detect these attacks.”

    He believes any package that has a pre-install or post-install script added should display warnings to everyone on the npm site and before package installation.

    The post Massive NPM Supply-Chain Attack Targets ENS-Linked Libraries in Shai Hulud Breach appeared first on Cryptonews.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Press Room

    Related Posts

    BlackRock Just Bought $600 Million in BTC — What Do They Know?

    March 16, 2026

    Solana Eyes Key $100 Resistance on Rising ETF Demand

    March 16, 2026

    XRP Price Stuck in ‘Painfully Slow’ Consolidation as BMIC’s Quantum-Safe Crypto Presale Nears $500K

    March 16, 2026
    Leave A Reply Cancel Reply

    LATEST NEWS

    Oscars 2026: Photos and Details You Might Have Missed

    March 16, 2026

    Current energy price spikes are disinflationary – Ironsides Macroeconomics

    March 16, 2026

    Meta Might Be Creating the New Blueprint for an AI-First Company

    March 16, 2026

    J.P. Morgan outlines CRM options play for uncertain Iran war outcome (CRM:NYSE)

    March 16, 2026
    POPULAR
    Business

    The Business of Formula One

    May 27, 2023
    Business

    Weddings and divorce: the scourge of investment returns

    May 27, 2023
    Business

    How F1 found a secret fuel to accelerate media rights growth

    May 27, 2023
    Advertisement
    Load WordPress Sites in as fast as 37ms!

    Archives

    • March 2026
    • February 2026
    • January 2026
    • December 2025
    • November 2025
    • October 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • May 2023

    Categories

    • Business
    • Crypto
    • Economy
    • Forex
    • Futures & Commodities
    • Investing
    • Market Data
    • Money
    • News
    • Personal Finance
    • Politics
    • Stocks
    • Technology

    Your source for the serious news. This demo is crafted specifically to exhibit the use of the theme as a news site. Visit our main page for more demos.

    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.