No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Sunday, March 22, 2026
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Cryptocurrency

New NPM Supply-Chain Attack Compromises ENS and Crypto Code

by TheAdviserMagazine
4 months ago
in Cryptocurrency
Reading Time: 2 mins read
A A
New NPM Supply-Chain Attack Compromises ENS and Crypto Code
Share on FacebookShare on TwitterShare on LInkedIn


A major JavaScript supply-chain attack has compromised hundreds of software packages — including at least 10 used widely across the crypto ecosystem — according to new research from cybersecurity firm Aikido Security.

In a Monday post, Charlie Eriksen, a researcher at Aikido Security, shared the names of over 400 packages that show signs of infection with the “Shai Hulud” self-replicating malware used in an ongoing JavaScript NPM library supply chain attack. Eriksen said he validated each detection to avoid false positives.

Many of the cryptocurrency-related packages involved receive tens of thousands of downloads per week and have numerous other packages that require them to function. In an X post published earlier today, Eriksen also warned the Ethereum Name Service (ENS) team that several of their packages are affected.

Source: Charlie Eriksen

Shai Hulud is part of a broader supply chain attack trend. In Early September, the largest NPM attack reported to date saw hackers only steal $50 million of crypto. Amazon Web Services noted that this first attack was followed by the Shai-Hulud worm spreading autonomously just a week later.

While the previous attack directly targeted crypto to steal assets, Shai-Hulud is a general-purpose credential-stealing malware that spreads autonomously across developer infrastructure. If the infected environment contains wallet keys, the malware will steal them as “secrets” like any other credential.

Related: Failed NPM exploit highlights looming threat to crypto security: Exec

Which crypto packages are affected?

Among all the affected packages, at least 10 were specifically related to the cryptocurrency industry, and nearly all were tied to the ENS, a human-readable address name service. Among the affected packages are ENS’s content-hash, with almost 36,000 weekly downloads, and 91 software packages depending on it, as well as address-encoder, with over 37,500 weekly downloads.

Other ENS packages affected include ensjs (over 30,000 weekly downloads), ens-validation (1,750 weekly downloads), ethereum-ens (12,650 weekly downloads), and ens-contracts (nearly 3,100 weekly downloads). A cryptocurrency-related package unrelated to ENS, called crypto-addr-codec, was also compromised, with almost 35,000 downloads.

Related: $27 million gone, no private keys exposed: How the BigONE hack happened

Popular non-crypto packages affected

Non-crypto-related packages affected include some offered by the corporate automation platform Zapier, including one with over 40,000 downloads per week and many not far behind. In a subsequent post, Eriksen pointed to other packages that were infected, some with nearly 70,000 weekly downloads, and to another package seeing well over 1.5 million weekly downloads.

“The scope of this new Shai Hulud attack is frankly massive; we’re still working through the queue to confirm it all,” Eriksen wrote on X.

“It’ll make the previous attack look like nothing.“

Researchers at cybersecurity firm Wiz claim to have “spotted over 25,000 affected repositories across ~350 unique users, 1,000 new repositories are being added consistently every 30 minutes in the last couple of hours.” The company recommends “immediate investigation and remediation” for any environment using npm.

Magazine: ‘Help! My robot vac is stealing my Bitcoin’: When smart devices attack



Source link

Tags: attackCodeCompromisesCryptoENSNPMsupplychain
ShareTweetShare
Previous Post

The irony of predicting markets: Nithin Kamath flags an expensive mistake traders can’t do without

Next Post

SEBI Unveils New Framework for Materiality of Related Party Transactions

Related Posts

edit post
CoinDCX Denies Any Link to Fraud as Founders Cited in India Investigation

CoinDCX Denies Any Link to Fraud as Founders Cited in India Investigation

by TheAdviserMagazine
March 22, 2026
0

CoinDCX co-founders Sumit Gupta and Neeraj Khandelwal were reportedly drawn into a police investigation in India over the weekend tied...

edit post
Bitcoin’s Growing US Stocks Correlation Triggers 50% BTC Price Crash Setup

Bitcoin’s Growing US Stocks Correlation Triggers 50% BTC Price Crash Setup

by TheAdviserMagazine
March 22, 2026
0

Bitcoin (BTC) erased much of its US-Iran war-driven gains this week, moving back in sync with the broader downtrend in...

edit post
Resolv’s USR stablecoin depegs after M exploit hits supply

Resolv’s USR stablecoin depegs after $80M exploit hits supply

by TheAdviserMagazine
March 22, 2026
0

Resolv’s USR stablecoin depegged following an apparent smart contract exploit on Sunday that allowed an attacker to mint 80 million...

edit post
Legendary Analyst Shares Something Crypto Investors Should Know

Legendary Analyst Shares Something Crypto Investors Should Know

by TheAdviserMagazine
March 21, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Into the Cryptoverse founder Benjamin Cowen has...

edit post
Fed rate cut chance hits zero, threatening stagflation where Bitcoin thrives as a hedge against long term inflation

Fed rate cut chance hits zero, threatening stagflation where Bitcoin thrives as a hedge against long term inflation

by TheAdviserMagazine
March 21, 2026
0

Wall Street has spent months debating when the Federal Reserve will cut interest rates. Now, traders are considering if the...

edit post
U.S. Prepares for Peace Talks in Iran War as Trump Mulls ‘Winding Down’ Military Efforts

U.S. Prepares for Peace Talks in Iran War as Trump Mulls ‘Winding Down’ Military Efforts

by TheAdviserMagazine
March 21, 2026
0

The U.S.-Iran war could be close to ending as the U.S. prepares for peace talks with Iran. This comes as...

Next Post
edit post
SEBI Unveils New Framework for Materiality of Related Party Transactions

SEBI Unveils New Framework for Materiality of Related Party Transactions

edit post
What Makes Charles River Laboratories (CRL) an Investment Bet?

What Makes Charles River Laboratories (CRL) an Investment Bet?

  • Trending
  • Comments
  • Latest
edit post
Foreclosure Starts are Up 19%—These Counties are Seeing the Highest Distress

Foreclosure Starts are Up 19%—These Counties are Seeing the Highest Distress

February 24, 2026
edit post
7 States Reporting a Surge in Norovirus Cases

7 States Reporting a Surge in Norovirus Cases

February 22, 2026
edit post
The Growing Movement to End Property Taxes Continues in Kentucky, And What It Means For Investors

The Growing Movement to End Property Taxes Continues in Kentucky, And What It Means For Investors

March 2, 2026
edit post
Who Is Legally Next of Kin in North Carolina?

Who Is Legally Next of Kin in North Carolina?

February 28, 2026
edit post
Publix to Open 5 New Stores by End of April. See Upcoming Locations.

Publix to Open 5 New Stores by End of April. See Upcoming Locations.

March 20, 2026
edit post
Hidden Danger for Seniors: Why Radon Is Building Up in Basements Across 10 States

Hidden Danger for Seniors: Why Radon Is Building Up in Basements Across 10 States

March 17, 2026
edit post
Drywall Insurance: Best Companies, Costs and Coverage

Drywall Insurance: Best Companies, Costs and Coverage

0
edit post
Non-Intervention Without the Fairy Tale of Sovereignty

Non-Intervention Without the Fairy Tale of Sovereignty

0
edit post
I asked my mother what she thinks about when she looks at old photographs of herself and she said “I think about how worried I was and how little of it mattered” — and the simplicity of that sentence from a woman who spent decades carrying everything has been sitting in my chest for three weeks because it contains a permission I’m not sure I’m brave enough to take yet

I asked my mother what she thinks about when she looks at old photographs of herself and she said “I think about how worried I was and how little of it mattered” — and the simplicity of that sentence from a woman who spent decades carrying everything has been sitting in my chest for three weeks because it contains a permission I’m not sure I’m brave enough to take yet

0
edit post
The Five Capabilities CX Leaders Need Now — And How To Build Them At CX Forum West Five Capabilities CX Leaders Need In The AI Era

The Five Capabilities CX Leaders Need Now — And How To Build Them At CX Forum West Five Capabilities CX Leaders Need In The AI Era

0
edit post
Long-term care costs outpacing retirement income: AARP

Long-term care costs outpacing retirement income: AARP

0
edit post
CoinDCX Denies Any Link to Fraud as Founders Cited in India Investigation

CoinDCX Denies Any Link to Fraud as Founders Cited in India Investigation

0
edit post
CoinDCX Denies Any Link to Fraud as Founders Cited in India Investigation

CoinDCX Denies Any Link to Fraud as Founders Cited in India Investigation

March 22, 2026
edit post
Cuba begins to restore power after third nationwide collapse of the entire energy grid this month

Cuba begins to restore power after third nationwide collapse of the entire energy grid this month

March 22, 2026
edit post
I asked my mother what she thinks about when she looks at old photographs of herself and she said “I think about how worried I was and how little of it mattered” — and the simplicity of that sentence from a woman who spent decades carrying everything has been sitting in my chest for three weeks because it contains a permission I’m not sure I’m brave enough to take yet

I asked my mother what she thinks about when she looks at old photographs of herself and she said “I think about how worried I was and how little of it mattered” — and the simplicity of that sentence from a woman who spent decades carrying everything has been sitting in my chest for three weeks because it contains a permission I’m not sure I’m brave enough to take yet

March 22, 2026
edit post
Dashcams Are Becoming a Must‑Have for Florida Seniors — The Hidden Insurance Benefits

Dashcams Are Becoming a Must‑Have for Florida Seniors — The Hidden Insurance Benefits

March 22, 2026
edit post
Bitcoin’s Growing US Stocks Correlation Triggers 50% BTC Price Crash Setup

Bitcoin’s Growing US Stocks Correlation Triggers 50% BTC Price Crash Setup

March 22, 2026
edit post
The Five Capabilities CX Leaders Need Now — And How To Build Them At CX Forum West Five Capabilities CX Leaders Need In The AI Era

The Five Capabilities CX Leaders Need Now — And How To Build Them At CX Forum West Five Capabilities CX Leaders Need In The AI Era

March 22, 2026
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • CoinDCX Denies Any Link to Fraud as Founders Cited in India Investigation
  • Cuba begins to restore power after third nationwide collapse of the entire energy grid this month
  • I asked my mother what she thinks about when she looks at old photographs of herself and she said “I think about how worried I was and how little of it mattered” — and the simplicity of that sentence from a woman who spent decades carrying everything has been sitting in my chest for three weeks because it contains a permission I’m not sure I’m brave enough to take yet
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.