No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Wednesday, April 15, 2026
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Cryptocurrency

New NPM Supply-Chain Attack Compromises ENS and Crypto Code

by TheAdviserMagazine
5 months ago
in Cryptocurrency
Reading Time: 2 mins read
A A
New NPM Supply-Chain Attack Compromises ENS and Crypto Code
Share on FacebookShare on TwitterShare on LInkedIn


A major JavaScript supply-chain attack has compromised hundreds of software packages — including at least 10 used widely across the crypto ecosystem — according to new research from cybersecurity firm Aikido Security.

In a Monday post, Charlie Eriksen, a researcher at Aikido Security, shared the names of over 400 packages that show signs of infection with the “Shai Hulud” self-replicating malware used in an ongoing JavaScript NPM library supply chain attack. Eriksen said he validated each detection to avoid false positives.

Many of the cryptocurrency-related packages involved receive tens of thousands of downloads per week and have numerous other packages that require them to function. In an X post published earlier today, Eriksen also warned the Ethereum Name Service (ENS) team that several of their packages are affected.

Source: Charlie Eriksen

Shai Hulud is part of a broader supply chain attack trend. In Early September, the largest NPM attack reported to date saw hackers only steal $50 million of crypto. Amazon Web Services noted that this first attack was followed by the Shai-Hulud worm spreading autonomously just a week later.

While the previous attack directly targeted crypto to steal assets, Shai-Hulud is a general-purpose credential-stealing malware that spreads autonomously across developer infrastructure. If the infected environment contains wallet keys, the malware will steal them as “secrets” like any other credential.

Related: Failed NPM exploit highlights looming threat to crypto security: Exec

Which crypto packages are affected?

Among all the affected packages, at least 10 were specifically related to the cryptocurrency industry, and nearly all were tied to the ENS, a human-readable address name service. Among the affected packages are ENS’s content-hash, with almost 36,000 weekly downloads, and 91 software packages depending on it, as well as address-encoder, with over 37,500 weekly downloads.

Other ENS packages affected include ensjs (over 30,000 weekly downloads), ens-validation (1,750 weekly downloads), ethereum-ens (12,650 weekly downloads), and ens-contracts (nearly 3,100 weekly downloads). A cryptocurrency-related package unrelated to ENS, called crypto-addr-codec, was also compromised, with almost 35,000 downloads.

Related: $27 million gone, no private keys exposed: How the BigONE hack happened

Popular non-crypto packages affected

Non-crypto-related packages affected include some offered by the corporate automation platform Zapier, including one with over 40,000 downloads per week and many not far behind. In a subsequent post, Eriksen pointed to other packages that were infected, some with nearly 70,000 weekly downloads, and to another package seeing well over 1.5 million weekly downloads.

“The scope of this new Shai Hulud attack is frankly massive; we’re still working through the queue to confirm it all,” Eriksen wrote on X.

“It’ll make the previous attack look like nothing.“

Researchers at cybersecurity firm Wiz claim to have “spotted over 25,000 affected repositories across ~350 unique users, 1,000 new repositories are being added consistently every 30 minutes in the last couple of hours.” The company recommends “immediate investigation and remediation” for any environment using npm.

Magazine: ‘Help! My robot vac is stealing my Bitcoin’: When smart devices attack



Source link

Tags: attackCodeCompromisesCryptoENSNPMsupplychain
ShareTweetShare
Previous Post

The irony of predicting markets: Nithin Kamath flags an expensive mistake traders can’t do without

Next Post

SEBI Unveils New Framework for Materiality of Related Party Transactions

Related Posts

edit post
Elon Musk’s X launches Smart Cashtags for crypto and stock tracking, adds one-tap trading access through Wealthsimple

Elon Musk’s X launches Smart Cashtags for crypto and stock tracking, adds one-tap trading access through Wealthsimple

by TheAdviserMagazine
April 14, 2026
0

Elon Musk’s X has rolled out Smart Cashtags, a new feature that lets users view real-time stock and crypto data...

edit post
Bitcoin Transfer Activity To Binance Slumps To Multi-Year Lows – Here’s What To Know

Bitcoin Transfer Activity To Binance Slumps To Multi-Year Lows – Here’s What To Know

by TheAdviserMagazine
April 14, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure While Bitcoin’s price has been struggling with fresh...

edit post
Ethereum Price Bounces Amid SEC’s DeFi Regulatory Clarity As Bulls Eye 00

Ethereum Price Bounces Amid SEC’s DeFi Regulatory Clarity As Bulls Eye $3000

by TheAdviserMagazine
April 14, 2026
0

Ethereum (ETH) price is one of the top gainers in the crypto market today, April 14, after a 9.27% gain...

edit post
Strategy’s STRC hits record trading volume after massive B Bitcoin purchase as market cap doubles since Friday

Strategy’s STRC hits record trading volume after massive $1B Bitcoin purchase as market cap doubles since Friday

by TheAdviserMagazine
April 14, 2026
0

Make CryptoSlate preferred on Strategy's perpetual preferred stock, STRC, played a key role in the company's Bitcoin strategy this week after it...

edit post
Forget All Dogecoin Predictions: This Chart Says DOGE Price Can Surge To

Forget All Dogecoin Predictions: This Chart Says DOGE Price Can Surge To $2

by TheAdviserMagazine
April 14, 2026
0

Crypto analyst Crypto Patel has predicted that the DOGE price can surge to $2, marking a new all-time high (ATH)...

edit post
Y Combinator Makes First All-Stablecoin Startup Investment – Crypto News Bitcoin News

Y Combinator Makes First All-Stablecoin Startup Investment – Crypto News Bitcoin News

by TheAdviserMagazine
April 14, 2026
0

Key Takeaways: Y Combinator invested $500,000 USDC in Totalis via Solana, marking its first all- stablecoin deal. 3 onchain transfers...

Next Post
edit post
SEBI Unveils New Framework for Materiality of Related Party Transactions

SEBI Unveils New Framework for Materiality of Related Party Transactions

edit post
What Makes Charles River Laboratories (CRL) an Investment Bet?

What Makes Charles River Laboratories (CRL) an Investment Bet?

  • Trending
  • Comments
  • Latest
edit post
Massachusetts loses billions in income after millionaire tax

Massachusetts loses billions in income after millionaire tax

March 24, 2026
edit post
Illinois’ Paid Leave for All Workers Act Takes Effect — Every Employee Now Gets Guaranteed Time Off

Illinois’ Paid Leave for All Workers Act Takes Effect — Every Employee Now Gets Guaranteed Time Off

March 27, 2026
edit post
Virginia Permits ADULT MIGRANT MEN To Attend High School

Virginia Permits ADULT MIGRANT MEN To Attend High School

March 30, 2026
edit post
A 58-year-old left NYC for Miami to save on taxes — then retired early thanks to hidden savings. Here’s the math

A 58-year-old left NYC for Miami to save on taxes — then retired early thanks to hidden savings. Here’s the math

March 30, 2026
edit post
Tax Flight Accelerates In Massachusetts

Tax Flight Accelerates In Massachusetts

April 6, 2026
edit post
Property Tax Relief & Income Tax Relief

Property Tax Relief & Income Tax Relief

April 1, 2026
edit post
Bitcoin Price Slides 2% as Michael Saylor Hints at More BTC Buys

Bitcoin Price Slides 2% as Michael Saylor Hints at More BTC Buys

0
edit post
Major gold holder launches self-custody wallet

Major gold holder launches self-custody wallet

0
edit post
Hampshire College to close after years-long turnaround effort comes up short

Hampshire College to close after years-long turnaround effort comes up short

0
edit post
Olivia and Liam Remain Most Popular Baby Names for 2024 | Social Security Matters

Olivia and Liam Remain Most Popular Baby Names for 2024 | Social Security Matters

0
edit post
Cómo hacer que un plan de salud con deducible alto funcione para tí

Cómo hacer que un plan de salud con deducible alto funcione para tí

0
edit post
Announcement of opinions for Friday, April 17

Announcement of opinions for Friday, April 17

0
edit post
BofA Securities initiates coverage on Groww with ‘buy’ rating; shares rally 4% to record high. Here’s what the brokerage said

BofA Securities initiates coverage on Groww with ‘buy’ rating; shares rally 4% to record high. Here’s what the brokerage said

April 15, 2026
edit post
Elon Musk’s X launches Smart Cashtags for crypto and stock tracking, adds one-tap trading access through Wealthsimple

Elon Musk’s X launches Smart Cashtags for crypto and stock tracking, adds one-tap trading access through Wealthsimple

April 14, 2026
edit post
Debt MF outflows hit record Rs 2.9 lakh crore in March

Debt MF outflows hit record Rs 2.9 lakh crore in March

April 14, 2026
edit post
Faulty Whirlpool Fridge? You May Be Eligible to Get up to 75% Back

Faulty Whirlpool Fridge? You May Be Eligible to Get up to 75% Back

April 14, 2026
edit post
7 Amazon Pill Organizers That Make It Impossible to Miss a Dose

7 Amazon Pill Organizers That Make It Impossible to Miss a Dose

April 14, 2026
edit post
Gloo forecasts 0M 2026 revenue while targeting adjusted EBITDA profitability in Q4 2026 following EMD deal (NASDAQ:GLOO)

Gloo forecasts $190M 2026 revenue while targeting adjusted EBITDA profitability in Q4 2026 following EMD deal (NASDAQ:GLOO)

April 14, 2026
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • BofA Securities initiates coverage on Groww with ‘buy’ rating; shares rally 4% to record high. Here’s what the brokerage said
  • Elon Musk’s X launches Smart Cashtags for crypto and stock tracking, adds one-tap trading access through Wealthsimple
  • Debt MF outflows hit record Rs 2.9 lakh crore in March
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.