A massive JavaScript-based Node Package Manager (npm) supply-chain attack has infiltrated code libraries connected to the Ethereum Name Service (ENS) A massive JavaScript-based Node Package Manager (npm) supply-chain attack has infiltrated code libraries connected to the Ethereum Name Service (ENS)

Massive NPM Supply-Chain Attack Targets ENS-Linked Libraries in Shai Hulud Breach

2025/11/25 02:28
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

A massive JavaScript-based Node Package Manager (npm) supply-chain attack has infiltrated code libraries connected to the Ethereum Name Service (ENS) and hundreds of older software packages, with over 10 widely used across the crypto ecosystem, according to cybersecurity firm Aikido Security.

Charlie Eriksen, a malware researcher at the security firm, disclosed that the supply-chain malware known as “Shai-Hulud: The Second Coming” has infected hundreds of packages and more than 25,000 GitHub repositories.

According to the findings, threat actors have embedded this malicious code into over 490 npm packages with more than 132 million monthly downloads, including prominent ones from ENS, Zapier, AsyncAPI, Browserbase, and Postman.

“If a developer installs one of these bad packages, the malware quietly runs during installation, before anything even finishes installing,” Eriksen said.

How the Shai-Hulud Supply-Chain Malware Works

As described by Akido security, the Shai-Hulud malware gains access to the developer’s machine or cloud environment during installation.

It then deploys an automated tool called TruffleHog to scan for sensitive data, including passwords, API keys, cloud tokens, and GitHub or NPM credentials.

Any discovered information is then uploaded to a public GitHub repository titled “Shai-Hulud: The Second Coming.”

If the stolen credentials include access to code repositories or package registries, attackers can leverage them to breach additional accounts and distribute more malicious packages, allowing the attack to propagate further.

Evolution from September’s Attack

The initial Shai-Hulud breach occurred in early September, marking the largest npm attack on record at the time, with hackers stealing $50 million in cryptocurrency.

Ledger hardware wallet noted that this first attack was followed by the Shai Hulud worm spreading autonomously a week later.

However, the infiltration method for this second wave appears substantially different.

The “Shai-Hulud: The Second Coming” first installs Bun via the file setup_bun.js, then uses it to execute bun_environment.js, which contains the actual malicious code.

Massive NPM Supply-Chain Attack Targets ENS-Linked Libraries in Shai Hulud BreachSource: Aikido Blog

It creates randomly named repositories with stolen data rather than using hardcoded names, and can infect up to 100 npm packages compared to 20 in the previous attack.

Self-Propagating Malware Exposes Blind Spot in NPM Packages

Charles Guillemet, Chief Technology Officer at crypto hardware wallet Ledger, alerted the community that the malware also targets API keys, Git credentials, and CI/CD secrets, then quietly exfiltrates everything.

“If you use affected packages: PLEASE check this carefully: consider your credentials and secrets compromised, audit your infrastructure, and rotate your credentials,” he cautioned.

He urged that anyone without close CI monitoring might consider shutting down their systems.

Florian Roth, Head of Research at Nextron Systems, also added that it’s becoming increasingly easy for threat actors to inject malware into sensitive systems due to blind spots in NPM packages.

According to his assessment, the industry previously fought malware at the OS level, but now the same behavior occurs one layer up, inside the software ecosystems people trust every day.

“NPM tokens, transitive deps, weak account hygiene, zero visibility… and suddenly a self-propagating worm runs through the supply chain like it’s 2003 again.”

He concluded that the recent Shai Hulud breach reveals the real blind spot is in package ecosystems acting as execution surfaces.

“Nobody monitors them, nobody hardens them, and attackers don’t even need an exploit to make them go wild,” he said.

JP Richardson, CEO of Exodus, the first public company in the U.S. to tokenize stocks on the blockchain, also questioned Microsoft for making it “easy” for threat actors to propagate malware.

In a November 24 post, Richardson said, “What I don’t understand [is] why Microsoft (npm owner) is not moving fast enough to detect these attacks.”

He believes any package that has a pre-install or post-install script added should display warnings to everyone on the npm site and before package installation.

Market Opportunity
ENS Logo
ENS Price(ENS)
$5.93
$5.93$5.93
-2.65%
USD
ENS (ENS) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Bitcoin ETFs Record Strongest Inflows Since July, Push Holdings to New High

Bitcoin ETFs Record Strongest Inflows Since July, Push Holdings to New High

The post Bitcoin ETFs Record Strongest Inflows Since July, Push Holdings to New High appeared on BitcoinEthereumNews.com. In brief Bitcoin ETPs saw a net inflow of 20,685 BTC last week, driven mostly by U.S. ETFs. The recent uptick in investor risk appetite is driven by rate cut expectations and new crypto IPOs. Despite institutional demand outpacing new Bitcoin supply, realized and implied volatility remain historically low. Bitcoin exchange-traded products globally logged net inflows of 20,685 BTC last week, the strongest weekly intake since July 22, according to digital assets firm K33 Research. The renewed momentum lifted U.S. spot bitcoin ETFs’ combined holdings to 1.32 million BTC, surpassing the previous peak set on July 30. U.S. Bitcoin ETF products contributed nearly 97% of last week’s 20,685 BTC ETP inflows, highlighting the surge in demand ahead of the FOMC meeting.  Bitcoin ETF inflows “tend to be one of the key determinants of Bitcoin’s performance,” André Dragosch, head of research for Europe at Bitwise Investments, told Decrypt, adding that the “percentage share of Bitcoin’s performance explained by changes in ETP flows” has reached a new all-time high. Compared with Ethereum ETF flows, “there appears to be a ‘re-rotation’ from Ethereum back to Bitcoin in terms of investor flows,” Dragosch said, citing their data. “Over the past week, flows into Bitcoin ETFs have surpassed new supply growth by a factor of 8.93 times, a key tailwind for Bitcoin’s recent performance.”  Analysts at K33 agree, writing that flows have been a key driver of bitcoin’s strength since ETF approvals earlier last year, and the latest surge signals an acceleration in demand that could underpin further price support. In the last 30 days, investors accumulated roughly 22,853 BTC via various products, outpacing the new supply of 14,056 BTC. This rising risk appetite for Bitcoin has supported the recent recovery, Bitwise noted in its Monday report. Fidelity’s FBTC product accounted for a substantial…
Share
BitcoinEthereumNews2025/09/18 10:19
What is Opinion, the project that's been making headlines lately? A 3-minute guide to understanding this new prediction market project.

What is Opinion, the project that's been making headlines lately? A 3-minute guide to understanding this new prediction market project.

CoinW Research Institute summary Recently, the prediction market sector has seen a surge in attention. Opinion, one of the most watched projects, attempts to transform
Share
PANews2026/03/11 08:33
The Importance of SEO for Businesses in Saskatoon

The Importance of SEO for Businesses in Saskatoon

In today’s competitive digital landscape, simply having a website is not enough. Businesses must ensure their websites are visible to potential customers who are
Share
Techbullion2026/03/11 08:25