Over 400 npm code libraries, including Ethereum Name Service packages, were compromised in a supply chain cyberattack detected Nov. 24. ENS Labs reports user assets and domains remain unaffected. The post ENS Npm Packages Compromised in Supply Chain Cyberattack Affecting 400 Libraries appeared first on Coinspeaker.Over 400 npm code libraries, including Ethereum Name Service packages, were compromised in a supply chain cyberattack detected Nov. 24. ENS Labs reports user assets and domains remain unaffected. The post ENS Npm Packages Compromised in Supply Chain Cyberattack Affecting 400 Libraries appeared first on Coinspeaker.

ENS Npm Packages Compromised in Supply Chain Cyberattack Affecting 400 Libraries

2025/11/25 04:41

Ethereum Name Service ENS $11.53 24h volatility: 3.2% Market cap: $436.61 M Vol. 24h: $62.46 M software packages were compromised in a supply chain cyberattack affecting over 400 code libraries on npm, a platform where developers share and download software tools. ENS Labs said user assets and domain names appear unaffected.

The team detected that packages starting with @ensdomains were affected around 5:49 a.m. UTC on Nov. 24 and has since updated package versions while changing security credentials, according to ENS Labs. ENS-operated websites including app.ens.domains showed no signs of impact.

The attack also compromised packages from Zapier, PostHog, Postman and AsyncAPI, according to Aikido Security, which first detected the campaign on Nov. 24.

Crypto Packages Among Victims

Several blockchain development libraries were caught in the broad attack. Affected packages include gate-evm-check-code2 and evm-checkcode-cli used for smart contract bytecode verification, create-hardhat3-app for Ethereum ETH $2 935 24h volatility: 5.4% Market cap: $355.26 B Vol. 24h: $32.16 B project scaffolding, and coinmarketcap-api for price data integration.

Other crypto libraries affected include ethereum-ens and crypto-addr-codec, which handles cryptocurrency address encoding. Over 40 packages within the @ensdomains scope were compromised.

The incident echoes a backdoor discovered in XRP Ledger packages in April, where malicious code was injected into xrpl.js to steal private keys.

How the Attack Works

Malicious packages were uploaded to npm between Nov. 21-23. The malware propagates by compromising maintainer accounts and injecting code into their packages. It executes automatically when developers run standard installation commands.

The malware collects developer passwords and access tokens from GitHub, npm and major cloud services. It publishes stolen data to public GitHub repositories and creates hidden access points on infected machines for future attacks.

A GitHub search shows 26,300 repositories now contain stolen credentials, spread across roughly 350 compromised accounts. The number continues to grow as the attack remains active.

Koi Security researchers discovered an additional threat. If the malware cannot steal credentials or send data out, it erases all files in the user’s home directory.

Developer Response

ENS Labs stated that developers who have not installed ENS packages within 11 hours of the 5:49 a.m. UTC detection are likely unaffected. Those who installed during that window should delete their node_modules folders, clear npm cache and change all credentials.

The incident follows a series of crypto security breaches that have tested infrastructure projects this year. GitHub is actively removing attacker-created repositories, though new ones continue to appear.

next

The post ENS Npm Packages Compromised in Supply Chain Cyberattack Affecting 400 Libraries appeared first on Coinspeaker.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

BFX Presale Raises $7.5M as Solana Holds $243 and Avalanche Eyes $1B Treasury — Best Cryptos to Buy in 2025

BFX Presale Raises $7.5M as Solana Holds $243 and Avalanche Eyes $1B Treasury — Best Cryptos to Buy in 2025

BFX presale hits $7.5M with tokens at $0.024 and 30% bonus code BLOCK30, while Solana holds $243 and Avalanche builds a $1B treasury to attract institutions.
Share
Blockchainreporter2025/09/18 01:07
Hyperliquid Strategies Inc. announces a $30M stock buyback program

Hyperliquid Strategies Inc. announces a $30M stock buyback program

The post Hyperliquid Strategies Inc. announces a $30M stock buyback program appeared on BitcoinEthereumNews.com. Hyperliquid Strategies Inc., a digital asset treasury company, has announced that its board approved a stock buyback of up to $30 million of the Company’s outstanding common stock, par value $0.01 per share.  The stock repurchase program will be in place for up to 12 months. The company states that repurchases will be made from time to time in open market transactions at prevailing market prices, at management’s discretion. Hyperliquid cites providing investors with access to HYPE as the initiative According to Hyperliquid, the actual timing, number, and value of shares repurchased under the program will be determined by management at its discretion. It will also depend on several factors, including the market price of HSI’s common stock, general market and economic conditions, and applicable legal requirements. Company CEO David Schamis stated that the repurchase is aimed at enhancing shareholder value and increasing the exposure of each share to Hyperliquid’s ecosystem native token HYPE through capital operations.  David Schamis stated, “We are fully committed to maximizing shareholder value through disciplined execution of our treasury strategy. Our primary objective is providing investors with efficient access to HYPE, the native token of the dominant Hyperliquid eco-system. We will use our cash to increase our shareholders’ per-share exposure to HYPE in the most efficient way possible.” However, the company cannot guarantee the final number of shares repurchased, and the repurchase program may be extended, suspended, or terminated at any time at the company’s discretion without further notice. Additionally, Hyperliquid Strategies Inc. is the core of the Hyperliquid ecosystem. Hyperion DeFi recently announced the receipt of a Kinetiq airdrop and a partnership with Native Markets. The company reports assert that these changes should make HYPE tokens more valuable and easier to trade. The company has also taken steps to expand its holdings, purchasing an…
Share
BitcoinEthereumNews2025/12/09 04:23