Skip to content

Ethereum Libraries Compromised in NPM Attack

Major JavaScript Supply-Chain Attack Affects Crypto Packages

  • Over 400 software packages are compromised, including at least 10 widely used in the cryptocurrency ecosystem.
  • Affected packages include those related to the ENS, with content-hash receiving nearly 36,000 weekly downloads.
  • The malware, known as “Shai Hulud,” is a credential-stealing tool that can autonomously spread across developer environments.
  • Cybersecurity researchers have identified over 25,000 affected repositories and continue to track new infections at a rate of about one every half hour.
  • In addition to crypto-related packages, popular non-crypto packages from platforms like Zapier are also impacted, with some seeing up to over a million downloads weekly.

This ongoing attack highlights vulnerabilities within the NPM ecosystem, particularly affecting critical libraries in the Ethereum Name Service and other crypto tools. Immediate action is recommended for developers using affected packages to mitigate risks associated with credential theft.

With tens of thousands of downloads per week for compromised packages like ENS’s content-hash, the scale of this attack poses significant risks to users and developers alike. (Source)

Share