• About Us
  • Careers
  • Contact
No Result
View All Result
Monday, February 16, 2026
DeFi Planet
  • News
    • People
    • Business
    • Crime
    • Regulation
    • Crypto
    • CBDC
  • Markets
    • Bitcoin
    • Ethereum
    • Stablecoins
    • Altcoins
    • Crypto ETFs
    • Memecoins
  • Policy
  • Articles
    • Press Releases
    • Opinion
    • Explainers
    • Guest Post
    • Sponsored
  • Directory
    • Companies
    • People
    • Products
    • Wallets
  • Multimedia
    • Videos
    • Podcasts
  • Learn
    • DeFi Basics
    • Tutorials
    • Reviews
    • Blockchain Fundamentals
  • Research
    • Case Studies
  • Explore
    • DeFi
    • Crypto Gaming
    • NFT
    • DAOs
    • Metaverse
    • Tokenization
    • Glossary
  • Jobs
  • Markets Pro
    • DeFi Planet Pro
    • Spend Crypto
    • Swap Crypto
    • Coin Prices
    • Crypto Exchanges
    • Crypto Analyzer
  • News
    • People
    • Business
    • Crime
    • Regulation
    • Crypto
    • CBDC
  • Markets
    • Bitcoin
    • Ethereum
    • Stablecoins
    • Altcoins
    • Crypto ETFs
    • Memecoins
  • Policy
  • Articles
    • Press Releases
    • Opinion
    • Explainers
    • Guest Post
    • Sponsored
  • Directory
    • Companies
    • People
    • Products
    • Wallets
  • Multimedia
    • Videos
    • Podcasts
  • Learn
    • DeFi Basics
    • Tutorials
    • Reviews
    • Blockchain Fundamentals
  • Research
    • Case Studies
  • Explore
    • DeFi
    • Crypto Gaming
    • NFT
    • DAOs
    • Metaverse
    • Tokenization
    • Glossary
  • Jobs
  • Markets Pro
    • DeFi Planet Pro
    • Spend Crypto
    • Swap Crypto
    • Coin Prices
    • Crypto Exchanges
    • Crypto Analyzer
No Result
View All Result
DeFi Planet
No Result
View All Result
Home Crime

JavaScript Supply-Chain Attack Infects Key Crypto Packages, ENS Libraries Hit Hard

Favour OkosodobyFavour Okosodo
24 November 2025
in Crime, News
Reading Time: 3 mins read
105 3
source: kiuwan.com

source: kiuwan.com

Quick Breakdown 

  • Over 400 JavaScript packages found infected with the self-replicating “Shai Hulud” malware.
  • At least 10 widely used crypto-related packages, mostly tied to Ethereum Name Service, were compromised.
  • Researchers warn the attack is rapidly escalating, adding 1,000 infected repositories every 30 minutes.

 

Massive NPM malware outbreak exposes crypto developers

A sweeping JavaScript supply-chain attack has compromised hundreds of open-source packages, including several foundational tools used across the crypto ecosystem, according to new research from cybersecurity firm Aikido Security.

Shai Hulud also compromised these packages:

– @ensdomains/ens-validation
– @ensdomains/content-hash
– ethereum-ens
– @ensdomains/react-ens-address
– @ensdomains/ens-contracts
– @ensdomains/ensjs
– @ensdomains/ens-archived-contracts
– @ensdomains/dnssecoraclejs@ensdomains

— Charlie Eriksen (@CharlieEriksen) November 24, 2025

The malware, known as “Shai Hulud,” was discovered embedded in more than 400 NPM libraries. Aikido researcher Charlie Eriksen said each detection was manually verified to eliminate false positives, calling the outbreak’s scale “massive.”

Shai Hulud is part of a growing wave of supply-chain attacks targeting developer infrastructure. While an earlier NPM breach in September led to the theft of $50 million in crypto, the new worm is designed for autonomous credential theft, quietly siphoning off secrets, including wallet keys stored on infected machines.

ENS tools among the hardest hit

More than 10 cryptocurrency-related packages have been confirmed compromised. Nearly all are tied to the Ethereum Name Service (ENS), prompting Eriksen to issue a direct warning to the ENS team on X.

Some of the most-downloaded infected libraries include content-hash, address-encoder, ensjs, ethereum-ens, ens-validation and ens-contracts. Another high-volume crypto tool, crypto-addr-codec, was also compromised, averaging nearly 35,000 downloads a week.

Given their deep integration within wallets, dApps, and blockchain infrastructure, the risk of downstream compromise is significant.

High-traffic non-crypto packages also infected

The malware’s reach extends far beyond crypto. Popular packages from corporate automation platform Zapier are among those affected, including one with more than 40,000 weekly downloads.

Eriksen later identified additional infected libraries approaching 70,000 weekly downloads, and one exceeding 1.5 million downloads per week, underscoring how deeply the worm has penetrated the NPM ecosystem.

Researchers warn outbreak is accelerating

Cybersecurity firm Wiz reported detecting over 25,000 infected repositories spanning 350+ users, with roughly 1,000 new compromised repositories appearing every 30 minutes over the past few hours.

The firm urged all developers using NPM to begin immediate audits, dependency checks, and remediation of environments. In April, the XRP Ledger Foundation flagged a critical security vulnerability in its official JavaScript library, a widely used tool for developers to interact with the XRP Ledger blockchain. 

 

If you would like to read more articles like this, visit DeFi Planet and follow us on Twitter, LinkedIn, Facebook, Instagram, and CoinMarketCap Community.

Take control of your crypto  portfolio with MARKETS PRO, DeFi Planet’s suite of analytics tools.”

Share63Tweet40Share11
Favour Okosodo

Favour Okosodo

Experienced web content writer with a strong command of SEO, specializing in creating concise, engaging content that drives traffic and enhances conversions across diverse industries.

Related Posts

source: ambito.com
DeFi

Stani Kulechov Sees $50T Opportunity in Tokenized “Abundance Assets”

16 February 2026
source:  coincentral.com
Bitcoin

Strategy to Convert $6B Bond Debt Into Equity as Bitcoin Strategy Faces Market Pressure

16 February 2026
source: theblock.co
News

Animoca Brands Secures Dubai VARA Licence to Expand Institutional Crypto Services

16 February 2026
source: techeconomy.ng
Bitcoin

Bitcoin Shows Rising Bear Market Signals as Large Drawdowns Increase

16 February 2026

Editor's Picks

DeFi Aggregators Explained: How to Optimize Returns and Cut Costs

DeFi Aggregators Explained: How to Optimize Returns and Cut Costs

byOlajumoke Oyalekeand1 others
23 January 2026
0

DeFi Insurance 101: How It Works, Benefits, and Risks

byOlajumoke Oyaleke
10 October 2025
0

How to Use a Crypto Hardware Wallet: A Step-by-Step Guide

How to Use a Crypto Hardware Wallet: A Step-by-Step Guide

byOlayinka Sodiq
12 August 2025
0

What Is a Rebase Token and How Does It Work?

What Is a Rebase Token and How Does It Work?

byOlajumoke Oyaleke
28 June 2025
0

What Are Fractional NFTs, and How Do They Work?

What Are Fractional NFTs, and How Do They Work?

byBlessing Lisafi
7 February 2024
0

Read More

Chain of Thoughts

The Nation-State FOMO: Are Strategic Bitcoin Reserves Genuine Policy or Political Theatre?

The Nation-State FOMO: Are Strategic Bitcoin Reserves Genuine Policy or Political Theatre?

byOlu Omoyele
28 December 2025
0

...

The Centralization Paradox: How Structural Forces Pull Crypto Back to Gatekeepers

The Centralization Paradox: How Structural Forces Pull Crypto Back to Gatekeepers

byOlu Omoyele
29 November 2025
0

...

SocialFi and the Tokenization of Influence

SocialFi and the Tokenization of Influence

byOlu Omoyele
31 October 2025
0

...

The Aesthetics of Web3: Why Vibe Matters in Decentralized Communities

The Aesthetics of Web3: Why Vibe Matters in Decentralized Communities

byOlu Omoyele
27 September 2025
0

...

Markets Update

Your Weekend Crypto Roundup | February 2026 (Week 2)

3 days ago

Your Weekend Crypto Roundup | February 2026 (Week 1)

1 week ago

How South Korea Customs Uncovered a $102M Crypto Laundering Scheme

2 weeks ago

What Google Play’s FIU Requirement Means for Offshore Crypto Exchanges in Asia

2 weeks ago

Why Hong Kong’s Crypto Industry Pushed Back on OECD Reporting Rules

2 weeks ago

How Stablecoin Yield Prohibitions Could Undermine the US Dollar

2 weeks ago
Read More

Events

Hedera DevDay 2026
Hedera DevDay 2026
17 Feb 26
Denver
ETHDenver 2026
ETHDenver 2026
18 Feb 26
Denver
Crypto Expo Europe 2026
Crypto Expo Europe 2026
1 Mar 26
Bucharest
DC Blockchain summit 2026
DC Blockchain summit 2026
17 Mar 26
Washington
Next Block Expo 2026
Next Block Expo 2026
24 Mar 26
Warsaw

Spotlight

Ethereum Solana Bitcoin RWA Tokenization

Press Releases

Phemex Astral Trading League (PATL) Goes Live, Building a Sustainable Seasonal Trading Progression System

bychainwire
12 February 2026
0

Cango Inc. Closed the US$10.5 Million Equity Investment and Secured US$65 Million Additional Equity Investments

bychainwire
12 February 2026
0

BYDFi Joins Solana Accelerate APAC at Consensus Hong Kong, Expanding Solana Ecosystem Engagement

bychainwire
12 February 2026
0

Flipster FZE Secures In-Principle Approval from VARA, Reinforcing Commitment to Regulated Crypto Access

bychainwire
12 February 2026
0

Wallet in Telegram Launches Cross Chain Deposits in Self Custodial TON Wallet

bychainwire
11 February 2026
0

Read More

ADVERTISING

ABOUT

TEAM

CAREERS

CONTACT

TERMS & CONDITIONS

PRIVACY POLICY

© Copyright 2026 DeFi Planet

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • News
    • People
    • Business
    • Crime
    • Regulation
    • Crypto
    • CBDC
  • Markets
    • Bitcoin
    • Ethereum
    • Stablecoins
    • Altcoins
    • Crypto ETFs
    • Memecoins
  • Policy
  • Articles
    • Press Releases
    • Opinion
    • Explainers
    • Guest Post
    • Sponsored
  • Directory
    • Companies
    • People
    • Products
    • Wallets
  • Multimedia
    • Videos
    • Podcasts
  • Learn
    • DeFi Basics
    • Tutorials
    • Reviews
    • Blockchain Fundamentals
  • Research
    • Case Studies
  • Explore
    • DeFi
    • Crypto Gaming
    • NFT
    • DAOs
    • Metaverse
    • Tokenization
    • Glossary
  • Jobs
  • Markets Pro
    • DeFi Planet Pro
    • Spend Crypto
    • Swap Crypto
    • Coin Prices
    • Crypto Exchanges
    • Crypto Analyzer

© Copyright 2024 DeFi Planet   |   Terms & Conditions   |   Privacy Policy

-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00