NPM Supply-Chain Attack Compromises 400+ Packages, ENS Libraries Targeted

Published at 2025-11-24 12:30:08

A security researcher reported that the Shai Hulud malware has compromised over 400 NPM libraries, with at least 10 cryptocurrency-related packages affected — most linked to the Ethereum Name Service (ENS) ecosystem. The injected code appears in dependencies used across projects, raising the likelihood that wallets, dapps, or tooling could ingest malicious updates indirectly via trusted packages.

This incident underscores persistent supply-chain vulnerabilities in open-source tooling. For ENS users and developers the risk includes compromised key material or automated actions if any build or runtime environment pulled infected packages. Maintainers should audit recent dependency changes, revoke or rotate exposed credentials where appropriate, and publish patched releases. Users should update to clean package versions and verify integrity before deploying. The breach is a reminder that dependency hygiene and provenance checks are now critical components of crypto infrastructure security.

Share on:

Related news

Yearn Recovers $2.39M of $9M After yETH Stableswap Exploit

Yearn Finance has recovered $2.39 million of roughly $9 million stolen after a flaw was exploited in a custom yETH Stableswap pool. Recovery efforts are ongoing as teams trace funds and try to secure remaining assets.

Published at 2025-12-03 08:30:23
Yearn Finance Hit by $9M DeFi Exploit; $2.39M pxETH Recovered

Yearn Finance confirmed a breach of a custom yETH stableswap pool that resulted in about $9 million in losses. The protocol recovered roughly $2.39 million in pxETH and the incident highlights ongoing security risks in custom DeFi pools.

Published at 2025-12-01 19:15:10
Malformed Transaction Exploit Triggers Emergency Response on Cardano

In November 2025 a malformed transaction exploited a deserialization bug on Cardano, prompting emergency interventions across the network. The incident has reignited scrutiny over the project's governance and update processes.

Published at 2025-12-01 15:45:08
Dunamu CEO Apologizes After Upbit Breach as Solana-Linked Losses Revised

Dunamu’s CEO apologized after a security breach at Upbit prompted the exchange to revise its estimated losses tied to Solana-related activity. The incident heightens scrutiny of exchange security and hot-wallet management.

Published at 2025-11-28 10:45:23
Upbit Fully Reimburses Users After ₩38.6B Hack

Upbit said it fully repaid 38.6 billion won in user assets using its own reserves after a recent security breach. The exchange says no customer balances were lost.

Published at 2025-11-28 10:15:11