Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Crypto News Ethereum

    New NPM Supply Chain Hack Threatens ENS and Cryptocurrency Security

    24 November 2025
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    New Npm Supply Chain Hack Threatens Ens And Cryptocurrency Security
    New Npm Supply Chain Hack Threatens Ens And Cryptocurrency Security

    Major Supply-Chain Attack Targets Crypto-Related Software Packages

    A significant JavaScript supply-chain attack has compromised over 400 software packages, including at least 10 heavily used within the cryptocurrency ecosystem. The breach was uncovered by cybersecurity firm Aikido Security, highlighting the evolving threat landscape faced by developers and users alike.

    In a detailed blog post, researcher Charlie Eriksen outlined the scope of the infection, identifying packages infected with the “Shai Hulud” malware—an autonomous, self-replicating strain designed to spread across developer environments. Eriksen confirmed the validity of each detection to prevent false positives. Many of these packages are responsible for critical functions, with some receiving tens of thousands of weekly downloads, emphasizing the widespread potential impact.

    Of particular concern are the affected packages associated with the Ethereum Name Service (ENS), which facilitate human-readable blockchain addresses. Notable among these are ENS’s content-hash, with nearly 36,000 weekly downloads, and address-encoder, with over 37,500 weekly downloads. Other ENS packages, such as ensjs, ens-validation, ethereum-ens, and ens-contracts, are also compromised. A separate package, crypto-addr-codec, unrelated to ENS, with nearly 35,000 weekly downloads, was also affected.

    Source: Charlie Eriksen

    This incident is part of a broader trend of supply-chain attacks. In September, the largest NPM attack to date resulted in approximately $50 million stolen from crypto assets. Amazon Web Services highlighted that this incident was followed by the spread of the Shai-Hulud worm, which replicated itself across environments post-initial breach.

    Unlike previous targeted thefts, Shai Hulud primarily acts as a credential-stealer, spreading autonomously and harvesting wallet keys and other secrets stored within infected environments. This capability poses a significant threat to the security of blockchain assets if such secrets are stored insecurely.

    Scope of the Affected Packages

    Among the impacted packages, at least 10 are directly related to cryptocurrency functions, predominantly tied to the ENS ecosystem. Packages such as content-hash, with nearly 36,000 weekly downloads, and address-encoder, exceeding 37,500 downloads, are critical components used by developers to handle address and name resolution. Other key packages affected include ensjs, ens-validation, ethereum-ens, and ens-contracts.

    Beyond crypto, several non-crypto packages are compromised, including popular tools from Zapier, like @zapier/secret-scrubber, with over 40,000 weekly downloads. Eriksen warned that affected packages with high download volumes, some approaching 70,000 weekly downloads, underscore the widespread reach of the malware.

    Researchers from Wiz estimate that over 25,000 repositories across hundreds of users have been impacted, with new compromised repositories added every 30 minutes. The cybersecurity community urges immediate investigations and remediation efforts for any environment utilizing npm packages.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Crypto Sell-Off Triggers $1.6b Liquidations As Bitcoin Etf Outflows Hit $3.67b

    Crypto Sell-Off Triggers $1.6B Liquidations as Bitcoin ETF Outflows Hit $3.67B

    20 minutes ago
    Maelstrom: Worldcoin An Overlooked Bet In The Ai Ipo Wave

    Maelstrom: Worldcoin an Overlooked Bet in the AI IPO Wave

    48 minutes ago
    Us Democrats Push For Ftc Probe Into Prediction Markets

    US Democrats Push for FTC Probe Into Prediction Markets

    2 hours ago
    Bitcoin Longs Liquidated Over $600m As Btc Tests $60k

    Bitcoin Longs Liquidated Over $600M as BTC Tests $60K

    3 hours ago
    Crypto: 67% Of Banned Anthropic Accounts Aided Ai Cyberattacks

    Crypto: 67% of banned Anthropic accounts aided AI cyberattacks

    5 hours ago
    Cftc Joins Sec In Ending No-Deny Settlements For Crypto Enforcement

    CFTC Joins SEC in Ending No-Deny Settlements for Crypto Enforcement

    7 hours ago

    Search Crypto News

    Featured Crypto News

    How Ai Is Changing Music: Virtual Artist Lunayah Releases "new Beginning"

    How AI Is Changing Music: Virtual Artist Lunayah Releases “New Beginning”

    1 June 2026
    Tangem Wallet Launches New Promo With Btc Rewards And Prize Draw

    Tangem Wallet launches new promo with BTC rewards and prize draw

    4 May 2026

    Latest News

    • Crypto Sell-Off Triggers $1.6B Liquidations as Bitcoin ETF Outflows Hit $3.67B
    • Maelstrom: Worldcoin an Overlooked Bet in the AI IPO Wave
    • US Democrats Push for FTC Probe Into Prediction Markets
    • Bitcoin Longs Liquidated Over $600M as BTC Tests $60K
    • Crypto: 67% of banned Anthropic accounts aided AI cyberattacks
    • CFTC Joins SEC in Ending No-Deny Settlements for Crypto Enforcement
    • CFTC Scraps No-Deny Clause in Settlements, Signals Enforcement Shift
    • Israel Tax Authority Deems Voluntary Crypto Disclosures Inadequate
    • Israel Tax Authority Dissatisfied With Voluntary Crypto Disclosures
    • Wyoming EO Shapes AI Data Center Development, Impact on Crypto Infra

    Join 17,000+ Crypto Followers

    • Facebook2.3K
    • Twitter4.3K
    • Instagram5.6K
    • LinkedIn4K
    • Telegram52
    • Threads800
    Kraken Pro 300x250
    Bitpanda

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    📞 +971 50 449 2025
    ✉️ info@cryptobreaking.com
    📍Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    Global Blockchain Show - Riyadh
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!