Major Supply-Chain Attack Targets Crypto-Related Software Packages A significant JavaScript supply-chain attack has compromised over 400 software packages, including at least 10 heavily used within the cryptocurrency ecosystem. The breach was uncovered by cybersecurity firm Aikido Security, highlighting the evolving threat landscape faced by developers and users alike. In a detailed blog post, researcher Charlie [...]Major Supply-Chain Attack Targets Crypto-Related Software Packages A significant JavaScript supply-chain attack has compromised over 400 software packages, including at least 10 heavily used within the cryptocurrency ecosystem. The breach was uncovered by cybersecurity firm Aikido Security, highlighting the evolving threat landscape faced by developers and users alike. In a detailed blog post, researcher Charlie [...]

New NPM Supply Chain Hack Threatens ENS and Cryptocurrency Security

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com
New Npm Supply Chain Hack Threatens Ens And Cryptocurrency Security

Major Supply-Chain Attack Targets Crypto-Related Software Packages

A significant JavaScript supply-chain attack has compromised over 400 software packages, including at least 10 heavily used within the cryptocurrency ecosystem. The breach was uncovered by cybersecurity firm Aikido Security, highlighting the evolving threat landscape faced by developers and users alike.

In a detailed blog post, researcher Charlie Eriksen outlined the scope of the infection, identifying packages infected with the “Shai Hulud” malware—an autonomous, self-replicating strain designed to spread across developer environments. Eriksen confirmed the validity of each detection to prevent false positives. Many of these packages are responsible for critical functions, with some receiving tens of thousands of weekly downloads, emphasizing the widespread potential impact.

Of particular concern are the affected packages associated with the Ethereum Name Service (ENS), which facilitate human-readable blockchain addresses. Notable among these are ENS’s content-hash, with nearly 36,000 weekly downloads, and address-encoder, with over 37,500 weekly downloads. Other ENS packages, such as ensjs, ens-validation, ethereum-ens, and ens-contracts, are also compromised. A separate package, crypto-addr-codec, unrelated to ENS, with nearly 35,000 weekly downloads, was also affected.

Source: Charlie Eriksen

This incident is part of a broader trend of supply-chain attacks. In September, the largest NPM attack to date resulted in approximately $50 million stolen from crypto assets. Amazon Web Services highlighted that this incident was followed by the spread of the Shai-Hulud worm, which replicated itself across environments post-initial breach.

Unlike previous targeted thefts, Shai Hulud primarily acts as a credential-stealer, spreading autonomously and harvesting wallet keys and other secrets stored within infected environments. This capability poses a significant threat to the security of blockchain assets if such secrets are stored insecurely.

Scope of the Affected Packages

Among the impacted packages, at least 10 are directly related to cryptocurrency functions, predominantly tied to the ENS ecosystem. Packages such as content-hash, with nearly 36,000 weekly downloads, and address-encoder, exceeding 37,500 downloads, are critical components used by developers to handle address and name resolution. Other key packages affected include ensjs, ens-validation, ethereum-ens, and ens-contracts.

Beyond crypto, several non-crypto packages are compromised, including popular tools from Zapier, like @zapier/secret-scrubber, with over 40,000 weekly downloads. Eriksen warned that affected packages with high download volumes, some approaching 70,000 weekly downloads, underscore the widespread reach of the malware.

Researchers from Wiz estimate that over 25,000 repositories across hundreds of users have been impacted, with new compromised repositories added every 30 minutes. The cybersecurity community urges immediate investigations and remediation efforts for any environment utilizing npm packages.

This article was originally published as New NPM Supply Chain Hack Threatens ENS and Cryptocurrency Security on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.

Market Opportunity
ENS Logo
ENS Price(ENS)
$6.034
$6.034$6.034
-3.50%
USD
ENS (ENS) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

The post Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be appeared on BitcoinEthereumNews.com. Jordan Love and the Green Bay Packers are off to a 2-0 start. Getty Images The Green Bay Packers are, once again, one of the NFL’s better teams. The Cleveland Browns are, once again, one of the league’s doormats. It’s why unbeaten Green Bay (2-0) is a 8-point favorite at winless Cleveland (0-2) Sunday according to betmgm.com. The money line is also Green Bay -500. Most expect this to be a Packers’ rout, and it very well could be. But Green Bay knows taking anyone in this league for granted can prove costly. “I think if you look at their roster, the paper, who they have on that team, what they can do, they got a lot of talent and things can turn around quickly for them,” Packers safety Xavier McKinney said. “We just got to kind of keep that in mind and know we not just walking into something and they just going to lay down. That’s not what they going to do.” The Browns certainly haven’t laid down on defense. Far from. Cleveland is allowing an NFL-best 191.5 yards per game. The Browns gave up 141 yards to Cincinnati in Week 1, including just seven in the second half, but still lost, 17-16. Cleveland has given up an NFL-best 45.5 rushing yards per game and just 2.1 rushing yards per attempt. “The biggest thing is our defensive line is much, much improved over last year and I think we’ve got back to our personality,” defensive coordinator Jim Schwartz said recently. “When we play our best, our D-line leads us there as our engine.” The Browns rank third in the league in passing defense, allowing just 146.0 yards per game. Cleveland has also gone 30 straight games without allowing a 300-yard passer, the longest active streak in the NFL.…
Share
BitcoinEthereumNews2025/09/18 00:41
EUR/CHF slides as Euro struggles post-inflation data

EUR/CHF slides as Euro struggles post-inflation data

The post EUR/CHF slides as Euro struggles post-inflation data appeared on BitcoinEthereumNews.com. EUR/CHF weakens for a second straight session as the euro struggles to recover post-Eurozone inflation data. Eurozone core inflation steady at 2.3%, headline CPI eases to 2.0% in August. SNB maintains a flexible policy outlook ahead of its September 25 decision, with no immediate need for easing. The Euro (EUR) trades under pressure against the Swiss Franc (CHF) on Wednesday, with EUR/CHF extending losses for the second straight session as the common currency struggles to gain traction following Eurozone inflation data. At the time of writing, the cross is trading around 0.9320 during the American session. The latest inflation data from Eurostat showed that Eurozone price growth remained broadly stable in August, reinforcing the European Central Bank’s (ECB) cautious stance on monetary policy. The Core Harmonized Index of Consumer Prices (HICP), which excludes volatile items such as food and energy, rose 2.3% YoY, in line with both forecasts and the previous month’s reading. On a monthly basis, core inflation increased by 0.3%, unchanged from July, highlighting persistent underlying price pressures in the bloc. Meanwhile, headline inflation eased to 2.0% YoY in August, down from 2.1% in July and slightly below expectations. On a monthly basis, prices rose just 0.1%, missing forecasts for a 0.2% increase and decelerating from July’s 0.2% rise. The inflation release follows last week’s ECB policy decision, where the central bank kept all three key interest rates unchanged and signaled that policy is likely at its terminal level. While officials acknowledged progress in bringing inflation down, they reiterated a cautious, data-dependent approach going forward, emphasizing the need to maintain restrictive conditions for an extended period to ensure price stability. On the Swiss side, disinflation appears to be deepening. The Producer and Import Price Index dropped 0.6% in August, marking a sharp 1.8% annual decline. Broader inflation remains…
Share
BitcoinEthereumNews2025/09/18 03:08
CME pushes Solana, XRP into derivatives spotlight with new options

CME pushes Solana, XRP into derivatives spotlight with new options

CME Group is launching options for Solana and XRP futures this October. The move signals a major shift, acknowledging that institutional liquidity is now firmly expanding beyond the established dominance of Bitcoin and Ether. According to a press release dated…
Share
Crypto.news2025/09/18 01:18