Massive NPM Attack Infects Crypto & ENS Libraries—Thousands at Risk
A massive JavaScript supply-chain attack has compromised over 400 NPM libraries, including key crypto and ENS packages, with the Shai Hulud malware stealing credentials and spreading rapidly.
A sweeping JavaScript supply-chain attack has compromised over 400 NPM libraries, including at least 10 widely used in the crypto ecosystem, particularly those tied to Ethereum Name Service (ENS). The Shai Hulud malware, a self-replicating worm, was found embedded in these packages, enabling it to autonomously steal credentials and wallet keys from infected environments. The attack is rapidly escalating, with over 25,000 repositories affected and 1,000 new ones compromised every 30 minutes. High-profile packages such as content-hash, address-encoder, ensjs, ens-validation, ethereum-ens, ens-contracts, and crypto-addr-codec have been impacted, threatening the integrity of tools relied on by developers and potentially exposing sensitive secrets. The malware harvests credentials, replicates itself, and makes private repositories public, posing a significant risk to both crypto and non-crypto projects. Immediate investigation and remediation are urged for any developer using npm packages to prevent further compromise.