No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Thursday, May 7, 2026
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Cryptocurrency

New NPM Supply-Chain Attack Compromises ENS and Crypto Code

by TheAdviserMagazine
5 months ago
in Cryptocurrency
Reading Time: 2 mins read
A A
New NPM Supply-Chain Attack Compromises ENS and Crypto Code
Share on FacebookShare on TwitterShare on LInkedIn


A major JavaScript supply-chain attack has compromised hundreds of software packages — including at least 10 used widely across the crypto ecosystem — according to new research from cybersecurity firm Aikido Security.

In a Monday post, Charlie Eriksen, a researcher at Aikido Security, shared the names of over 400 packages that show signs of infection with the “Shai Hulud” self-replicating malware used in an ongoing JavaScript NPM library supply chain attack. Eriksen said he validated each detection to avoid false positives.

Many of the cryptocurrency-related packages involved receive tens of thousands of downloads per week and have numerous other packages that require them to function. In an X post published earlier today, Eriksen also warned the Ethereum Name Service (ENS) team that several of their packages are affected.

Source: Charlie Eriksen

Shai Hulud is part of a broader supply chain attack trend. In Early September, the largest NPM attack reported to date saw hackers only steal $50 million of crypto. Amazon Web Services noted that this first attack was followed by the Shai-Hulud worm spreading autonomously just a week later.

While the previous attack directly targeted crypto to steal assets, Shai-Hulud is a general-purpose credential-stealing malware that spreads autonomously across developer infrastructure. If the infected environment contains wallet keys, the malware will steal them as “secrets” like any other credential.

Related: Failed NPM exploit highlights looming threat to crypto security: Exec

Which crypto packages are affected?

Among all the affected packages, at least 10 were specifically related to the cryptocurrency industry, and nearly all were tied to the ENS, a human-readable address name service. Among the affected packages are ENS’s content-hash, with almost 36,000 weekly downloads, and 91 software packages depending on it, as well as address-encoder, with over 37,500 weekly downloads.

Other ENS packages affected include ensjs (over 30,000 weekly downloads), ens-validation (1,750 weekly downloads), ethereum-ens (12,650 weekly downloads), and ens-contracts (nearly 3,100 weekly downloads). A cryptocurrency-related package unrelated to ENS, called crypto-addr-codec, was also compromised, with almost 35,000 downloads.

Related: $27 million gone, no private keys exposed: How the BigONE hack happened

Popular non-crypto packages affected

Non-crypto-related packages affected include some offered by the corporate automation platform Zapier, including one with over 40,000 downloads per week and many not far behind. In a subsequent post, Eriksen pointed to other packages that were infected, some with nearly 70,000 weekly downloads, and to another package seeing well over 1.5 million weekly downloads.

“The scope of this new Shai Hulud attack is frankly massive; we’re still working through the queue to confirm it all,” Eriksen wrote on X.

“It’ll make the previous attack look like nothing.“

Researchers at cybersecurity firm Wiz claim to have “spotted over 25,000 affected repositories across ~350 unique users, 1,000 new repositories are being added consistently every 30 minutes in the last couple of hours.” The company recommends “immediate investigation and remediation” for any environment using npm.

Magazine: ‘Help! My robot vac is stealing my Bitcoin’: When smart devices attack



Source link

Tags: attackCodeCompromisesCryptoENSNPMsupplychain
ShareTweetShare
Previous Post

The irony of predicting markets: Nithin Kamath flags an expensive mistake traders can’t do without

Next Post

SEBI Unveils New Framework for Materiality of Related Party Transactions

Related Posts

edit post
Solana Eyes New Leg Up After Triangle Breakout –  Next?

Solana Eyes New Leg Up After Triangle Breakout – $96 Next?

by TheAdviserMagazine
May 7, 2026
0

As Solana (SOL) breaks out of a multi‑week pattern, some market observers suggest a retest of a key resistance level...

edit post
Kenyan Court Detains Man 7 Days Over 0,000 Crypto App Fraud Probe

Kenyan Court Detains Man 7 Days Over $440,000 Crypto App Fraud Probe

by TheAdviserMagazine
May 7, 2026
0

Key TakeawaysDetaining Dickson Nyakango over a $440K scam exposes retail risks; court resumes this month.After Kestrel flagged a 7% scam,...

edit post
JPMorgan, Mastercard Make US Treasury Transfer on XRP Ledger

JPMorgan, Mastercard Make US Treasury Transfer on XRP Ledger

by TheAdviserMagazine
May 6, 2026
0

Wall Street bank JPMorgan and credit card giant Mastercard said they have completed the first cross-border, cross-bank redemption of a...

edit post
Ondo, JPMorgan, Mastercard and Ripple complete tokenized Treasury pilot on XRP Ledger

Ondo, JPMorgan, Mastercard and Ripple complete tokenized Treasury pilot on XRP Ledger

by TheAdviserMagazine
May 6, 2026
0

Ondo Finance, Kinexys by J.P. Morgan, Mastercard and Ripple completed a pilot transaction linking tokenized US Treasuries on the XRP...

edit post
Retail Traders Get Crypto Access as Morgan Stanley Follows SoFi in Trading Push

Retail Traders Get Crypto Access as Morgan Stanley Follows SoFi in Trading Push

by TheAdviserMagazine
May 6, 2026
0

Not All Video Reviews Are Created Equal | Finance Magnates Not All Video Reviews Are Created Equal | Finance Magnates...

edit post
The Biggest XRP Treasury Company Is Adopting A New Strategy, Here’s What It Is

The Biggest XRP Treasury Company Is Adopting A New Strategy, Here’s What It Is

by TheAdviserMagazine
May 6, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure XRP treasury firm Evernorth’s CEO, Asheesh Birla,...

Next Post
edit post
SEBI Unveils New Framework for Materiality of Related Party Transactions

SEBI Unveils New Framework for Materiality of Related Party Transactions

edit post
What Makes Charles River Laboratories (CRL) an Investment Bet?

What Makes Charles River Laboratories (CRL) an Investment Bet?

  • Trending
  • Comments
  • Latest
edit post
Gavin Newsom issues ‘final warning’ amid California’s dire housing crisis — what’s at stake for millions of residents

Gavin Newsom issues ‘final warning’ amid California’s dire housing crisis — what’s at stake for millions of residents

May 3, 2026
edit post
Florida Warning: With Senior SNAP Benefits Averaging 8/Month, Thousands Risk Losing Assistance in 2026

Florida Warning: With Senior SNAP Benefits Averaging $188/Month, Thousands Risk Losing Assistance in 2026

April 27, 2026
edit post
Minnesota Wealth Tax | Intangible Personal Property Tax

Minnesota Wealth Tax | Intangible Personal Property Tax

May 6, 2026
edit post
10 Cheapest High Dividend Stocks With P/E Ratios Under 10

10 Cheapest High Dividend Stocks With P/E Ratios Under 10

April 13, 2026
edit post
Exclusive: America’s largest Black-owned bank launches podcast with mission to unlock hidden shame holding back generational wealth

Exclusive: America’s largest Black-owned bank launches podcast with mission to unlock hidden shame holding back generational wealth

April 29, 2026
edit post
NYC Mayor Mamdani knocked Ken Griffin in pied-a-terre tax promo. His firm calls the move ‘shameful’

NYC Mayor Mamdani knocked Ken Griffin in pied-a-terre tax promo. His firm calls the move ‘shameful’

April 23, 2026
edit post
Clearer Way to Benchmark Private Equity

Clearer Way to Benchmark Private Equity

0
edit post
Trafigura to build new aluminium smelter in Egypt

Trafigura to build new aluminium smelter in Egypt

0
edit post
8 Hacks for Setting up a New Life in Small-Town Panama

8 Hacks for Setting up a New Life in Small-Town Panama

0
edit post
Mortgage Rates Today, Thursday, May 7: A Substantial Drop

Mortgage Rates Today, Thursday, May 7: A Substantial Drop

0
edit post
Many adults who grew up watching their parents struggle with money carry a low background fear of running out for decades past the point where the math makes sense, finally realizing they aren’t budgeting for their future, but soothing the child who watched scarcity play out at the kitchen table

Many adults who grew up watching their parents struggle with money carry a low background fear of running out for decades past the point where the math makes sense, finally realizing they aren’t budgeting for their future, but soothing the child who watched scarcity play out at the kitchen table

0
edit post
Carbon Taxes by Country: Rankings, Design, and Administration

Carbon Taxes by Country: Rankings, Design, and Administration

0
edit post
Trafigura to build new aluminium smelter in Egypt

Trafigura to build new aluminium smelter in Egypt

May 7, 2026
edit post
8 Hacks for Setting up a New Life in Small-Town Panama

8 Hacks for Setting up a New Life in Small-Town Panama

May 7, 2026
edit post
Many adults who grew up watching their parents struggle with money carry a low background fear of running out for decades past the point where the math makes sense, finally realizing they aren’t budgeting for their future, but soothing the child who watched scarcity play out at the kitchen table

Many adults who grew up watching their parents struggle with money carry a low background fear of running out for decades past the point where the math makes sense, finally realizing they aren’t budgeting for their future, but soothing the child who watched scarcity play out at the kitchen table

May 7, 2026
edit post
Mortgage Rates Today, Thursday, May 7: A Substantial Drop

Mortgage Rates Today, Thursday, May 7: A Substantial Drop

May 7, 2026
edit post
Where California Went Wrong | Mises Institute

Where California Went Wrong | Mises Institute

May 7, 2026
edit post
Treasury expected to borrow  trillion this year—more than 6 billion every month

Treasury expected to borrow $2 trillion this year—more than $166 billion every month

May 7, 2026
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Trafigura to build new aluminium smelter in Egypt
  • 8 Hacks for Setting up a New Life in Small-Town Panama
  • Many adults who grew up watching their parents struggle with money carry a low background fear of running out for decades past the point where the math makes sense, finally realizing they aren’t budgeting for their future, but soothing the child who watched scarcity play out at the kitchen table
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.