Skip to content
btc Bitcoin $70,771 -0.06% eth Ethereum $2,158 0.35% usdt Tether $1 -0.01% xrp XRP $1 -0.41% bnb BNB $644 -0.06% usdc USDC $1 0.00% sol Solana $90 0.90% trx TRON $0 2.52% figr_heloc Figure Heloc $1 0.12% doge Dogecoin $0 0.28%

Shai Hulud malware infects over 400 npm libraries, including major ENS crypto packages

New NPM supply-chain attack compromises major ENS and crypto libraries
SHARE THIS ARTICLE

A major JavaScript supply-chain breach has hit the open-source ecosystem, with cybersecurity researchers confirming that more than 400 npm libraries were compromised by the self-replicating Shai Hulud malware. The discovery was detailed by Aikido Security researcher Charlie Eriksen, who said each flagged package was manually validated to avoid false positives. The incident is still unfolding, and early indications suggest it may be one of the most extensive npm infections seen to date.

Crypto packages compromised

Among the impacted libraries, at least ten are widely used within the cryptocurrency ecosystem, particularly those connected to the Ethereum Name Service (ENS). Several ENS dependencies central to wallet infrastructure and naming services were affected, prompting Eriksen to alert the ENS team directly on X. Packages such as content-hash, address-encoder, ensjs, ethereum-ens, ens-contracts and others many of which log tens of thousands of weekly downloads were found to contain malicious code. Another widely used crypto library, crypto-addr-codec, was also confirmed compromised.

Impact beyond crypto

The infection extends well past blockchain-related tooling. Multiple libraries associated with mainstream platforms such as Zapier were found compromised, including some with download counts in the tens of thousands. One affected package identified later in the review reportedly receives well over a million weekly downloads. The breadth of the incident underscores the systemic risk posed by compromised open-source dependencies across both fintech and traditional software development environments.

Rapid spread and growing risk

The Shai Hulud malware emerged shortly after a separate npm attack earlier in September one responsible for the theft of roughly $50 million in crypto assets. Unlike that targeted theft, Shai Hulud operates as a credential-stealing worm capable of spreading autonomously through developer environments. If wallet keys or other sensitive credentials are stored locally, the malware exfiltrates them just as it would any other secret. Researchers at Wiz estimated that more than 25,000 repositories have already been affected across hundreds of users, with new infected repositories appearing at a pace of roughly 1,000 every 30 minutes at the height of the outbreak.

Nazia is a seasoned journalist and editor with 6+ years of experience covering tech, AI, business, and crypto specializing in breaking news and market insights across blockchain and Web3.

Coin Headlines covers the latest news in crypto, blockchain, Web3, and markets, bringing you credible and up-to-date information on all the latest developments from around the world.

We focus on real-time news updates, market movements, whale transfers, and macroeconomic trends to keep you informed and engaged. Whether it’s Bitcoin price swings, altcoin updates, meme coin hype, regulatory changes, or major moves from the world of traditional finance, Coin Headlines gives you what you need to know, right when you need it.