No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Sunday, January 11, 2026
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Cryptocurrency

New NPM Supply-Chain Attack Compromises ENS and Crypto Code

by TheAdviserMagazine
2 months ago
in Cryptocurrency
Reading Time: 2 mins read
A A
New NPM Supply-Chain Attack Compromises ENS and Crypto Code
Share on FacebookShare on TwitterShare on LInkedIn


A major JavaScript supply-chain attack has compromised hundreds of software packages — including at least 10 used widely across the crypto ecosystem — according to new research from cybersecurity firm Aikido Security.

In a Monday post, Charlie Eriksen, a researcher at Aikido Security, shared the names of over 400 packages that show signs of infection with the “Shai Hulud” self-replicating malware used in an ongoing JavaScript NPM library supply chain attack. Eriksen said he validated each detection to avoid false positives.

Many of the cryptocurrency-related packages involved receive tens of thousands of downloads per week and have numerous other packages that require them to function. In an X post published earlier today, Eriksen also warned the Ethereum Name Service (ENS) team that several of their packages are affected.

Source: Charlie Eriksen

Shai Hulud is part of a broader supply chain attack trend. In Early September, the largest NPM attack reported to date saw hackers only steal $50 million of crypto. Amazon Web Services noted that this first attack was followed by the Shai-Hulud worm spreading autonomously just a week later.

While the previous attack directly targeted crypto to steal assets, Shai-Hulud is a general-purpose credential-stealing malware that spreads autonomously across developer infrastructure. If the infected environment contains wallet keys, the malware will steal them as “secrets” like any other credential.

Related: Failed NPM exploit highlights looming threat to crypto security: Exec

Which crypto packages are affected?

Among all the affected packages, at least 10 were specifically related to the cryptocurrency industry, and nearly all were tied to the ENS, a human-readable address name service. Among the affected packages are ENS’s content-hash, with almost 36,000 weekly downloads, and 91 software packages depending on it, as well as address-encoder, with over 37,500 weekly downloads.

Other ENS packages affected include ensjs (over 30,000 weekly downloads), ens-validation (1,750 weekly downloads), ethereum-ens (12,650 weekly downloads), and ens-contracts (nearly 3,100 weekly downloads). A cryptocurrency-related package unrelated to ENS, called crypto-addr-codec, was also compromised, with almost 35,000 downloads.

Related: $27 million gone, no private keys exposed: How the BigONE hack happened

Popular non-crypto packages affected

Non-crypto-related packages affected include some offered by the corporate automation platform Zapier, including one with over 40,000 downloads per week and many not far behind. In a subsequent post, Eriksen pointed to other packages that were infected, some with nearly 70,000 weekly downloads, and to another package seeing well over 1.5 million weekly downloads.

“The scope of this new Shai Hulud attack is frankly massive; we’re still working through the queue to confirm it all,” Eriksen wrote on X.

“It’ll make the previous attack look like nothing.“

Researchers at cybersecurity firm Wiz claim to have “spotted over 25,000 affected repositories across ~350 unique users, 1,000 new repositories are being added consistently every 30 minutes in the last couple of hours.” The company recommends “immediate investigation and remediation” for any environment using npm.

Magazine: ‘Help! My robot vac is stealing my Bitcoin’: When smart devices attack



Source link

Tags: attackCodeCompromisesCryptoENSNPMsupplychain
ShareTweetShare
Previous Post

The irony of predicting markets: Nithin Kamath flags an expensive mistake traders can’t do without

Next Post

SEBI Unveils New Framework for Materiality of Related Party Transactions

Related Posts

edit post
Saylor Posts “big Orange” — Is Another BTC Purchase Tomorrow?

Saylor Posts “big Orange” — Is Another BTC Purchase Tomorrow?

by TheAdviserMagazine
January 11, 2026
0

Strategy executive chairman Michael Saylor brought renewed focus to the firm’s Bitcoin position on January 11 after an X post...

edit post
Insiders sell government crypto database to violent home invaders as transparency laws backfire

Insiders sell government crypto database to violent home invaders as transparency laws backfire

by TheAdviserMagazine
January 11, 2026
0

A tax employee in Bobigny used internal software to compile dossiers on cryptocurrency specialists, billionaire Vincent Bolloré, prison guards, and...

edit post
Coinbase Outlines Bullish Markets Outlook as Global Liquidity and Scale Accelerate

Coinbase Outlines Bullish Markets Outlook as Global Liquidity and Scale Accelerate

by TheAdviserMagazine
January 10, 2026
0

Coinbase is accelerating its push to dominate global crypto trading, fueled by surging liquidity, expanding derivatives and spot markets, and...

edit post
Analyst Outlines The Bull Case For XRP And Why Price Will Hit All-Time High Soon

Analyst Outlines The Bull Case For XRP And Why Price Will Hit All-Time High Soon

by TheAdviserMagazine
January 10, 2026
0

XRP is now back to trading just above the $2 level after an early January rally briefly carried its price...

edit post
Bitcoin Network Mining Difficulty Falls in Jan 2026

Bitcoin Network Mining Difficulty Falls in Jan 2026

by TheAdviserMagazine
January 10, 2026
0

The Bitcoin (BTC) network mining difficulty, the relative computing challenge of adding a new block to the decentralized blockchain ledger,...

edit post
Tennessee targets Kalshi, Polymarket, and Crypto.com over sports betting

Tennessee targets Kalshi, Polymarket, and Crypto.com over sports betting

by TheAdviserMagazine
January 10, 2026
0

Key Takeaways Tennessee's Sports Wagering Committee has issued cease-and-desist orders to Kalshi, Polymarket, and Crypto.com. Regulators want the companies to...

Next Post
edit post
SEBI Unveils New Framework for Materiality of Related Party Transactions

SEBI Unveils New Framework for Materiality of Related Party Transactions

edit post
What Makes Charles River Laboratories (CRL) an Investment Bet?

What Makes Charles River Laboratories (CRL) an Investment Bet?

  • Trending
  • Comments
  • Latest
edit post
Most People Buy Mansions But This Virginia Lottery Winner Took the Lump Sum From a 8 Million Jackpot and Bought a Zero-Turn Lawn Mower Instead

Most People Buy Mansions But This Virginia Lottery Winner Took the Lump Sum From a $348 Million Jackpot and Bought a Zero-Turn Lawn Mower Instead

January 10, 2026
edit post
Utility Shutoff Policies Are Changing in Several Midwestern States

Utility Shutoff Policies Are Changing in Several Midwestern States

January 9, 2026
edit post
80-year-old Home Depot rival shuts down location, no bankruptcy

80-year-old Home Depot rival shuts down location, no bankruptcy

January 4, 2026
edit post
Tennessee theater professor reinstated, with 0,000 settlement, after losing his job over a Charlie Kirk-related social media post

Tennessee theater professor reinstated, with $500,000 settlement, after losing his job over a Charlie Kirk-related social media post

January 8, 2026
edit post
In an Ohio Suburb, Sprawl Is Being Transformed Into Walkable Neighborhoods

In an Ohio Suburb, Sprawl Is Being Transformed Into Walkable Neighborhoods

December 14, 2025
edit post
Democrats Insist On Taxing Tips        

Democrats Insist On Taxing Tips        

December 15, 2025
edit post
This CEO laid off nearly 80% of his staff because they refused to adopt AI fast enough

This CEO laid off nearly 80% of his staff because they refused to adopt AI fast enough

0
edit post
HealthTech, Access, and Financial Fluency: The Future of Women and Alts

HealthTech, Access, and Financial Fluency: The Future of Women and Alts

0
edit post
Mortgage Rates Today, Friday, January 9: An Even 6%

Mortgage Rates Today, Friday, January 9: An Even 6%

0
edit post
Wiz cofounder buys land for Binyamina homes for NIS 28m

Wiz cofounder buys land for Binyamina homes for NIS 28m

0
edit post
Fitness Peaks Earlier in Life Than You Might Think — but Now There’s Good News for Older People

Fitness Peaks Earlier in Life Than You Might Think — but Now There’s Good News for Older People

0
edit post
Is Ultra-High-Yield Enterprise Products Partners Your Ticket to Becoming a Millionaire?

Is Ultra-High-Yield Enterprise Products Partners Your Ticket to Becoming a Millionaire?

0
edit post
This CEO laid off nearly 80% of his staff because they refused to adopt AI fast enough

This CEO laid off nearly 80% of his staff because they refused to adopt AI fast enough

January 11, 2026
edit post
Is Ultra-High-Yield Enterprise Products Partners Your Ticket to Becoming a Millionaire?

Is Ultra-High-Yield Enterprise Products Partners Your Ticket to Becoming a Millionaire?

January 11, 2026
edit post
People who accomplish more before 9am than most do all day usually share these 8 quiet habits

People who accomplish more before 9am than most do all day usually share these 8 quiet habits

January 11, 2026
edit post
After January, These Preventive Screenings Are Still Covered, But Only Under Specific Plan Rules

After January, These Preventive Screenings Are Still Covered, But Only Under Specific Plan Rules

January 11, 2026
edit post
Wiz cofounder buys land for Binyamina homes for NIS 28m

Wiz cofounder buys land for Binyamina homes for NIS 28m

January 11, 2026
edit post
Saylor Posts “big Orange” — Is Another BTC Purchase Tomorrow?

Saylor Posts “big Orange” — Is Another BTC Purchase Tomorrow?

January 11, 2026
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • This CEO laid off nearly 80% of his staff because they refused to adopt AI fast enough
  • Is Ultra-High-Yield Enterprise Products Partners Your Ticket to Becoming a Millionaire?
  • People who accomplish more before 9am than most do all day usually share these 8 quiet habits
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.