JavaScript Supply Chain Attack: A Crypto Threat Emerges

New research from cybersecurity firm Aikido Security has revealed a major JavaScript supply chain attack, compromising hundreds of software packages – including at least 10 that are extensively used within the cryptocurrency ecosystem.

In a Monday announcement, Charlie Eriksen, a researcher at Aikido Security, disclosed the names of over 400 packages exhibiting signs of infection by the “Shai Hulud” self-replicating malware, which is being leveraged in an ongoing JavaScript NPM library supply chain attack. Eriksen stated that each detection was validated to minimize false positives.

Several of the impacted cryptocurrency-related packages receive tens of thousands of weekly downloads and are critical dependencies for numerous other packages. Eriksen also alerted the Ethereum Name Service (ENS) team via an X post, indicating that multiple ENS packages were affected.

Shai Hulud is indicative of a broader supply chain attack trend. Earlier in September, the largest reported NPM attack resulted in the theft of $50 million in cryptocurrency. Amazon Web Services noted that the initial attack was quickly followed by the autonomous spread of the Shai-Hulud worm within a week.

While the previous attack directly targeted crypto assets for theft, Shai-Hulud operates as a general-purpose credential-stealing malware, spreading autonomously across developer infrastructure. If the compromised environment contains wallet keys, the malware will exfiltrate them as “secrets,” similar to any other sensitive credential.

Affected Crypto Packages

Among the affected packages, at least 10 are specifically linked to the cryptocurrency industry, with a heavy concentration around ENS, a human-readable address name service. Notable impacted packages include ENS’s content-hash, boasting nearly 36,000 weekly downloads and 91 dependent software packages, and address-encoder, with over 37,500 weekly downloads.

Other affected ENS packages include ensjs (over 30,000 weekly downloads), ens-validation (1,750 weekly downloads), ethereum-ens (12,650 weekly downloads), and ens-contracts (nearly 3,100 weekly downloads). A non-ENS-related crypto package, crypto-addr-codec, was also compromised, seeing almost 35,000 downloads.

Popular Non-Crypto Packages Impacted

Affected packages extend beyond the cryptocurrency realm, impacting offerings from corporate automation platform Zapier, including one with over 40,000 weekly downloads and several others not far behind. Eriksen further identified other infected packages, some nearing 70,000 weekly downloads, and another exceeding 1.5 million weekly downloads.

“The scope of this new Shai Hulud attack is frankly massive; we’re still working through the queue to confirm it all,” Eriksen wrote on X.

“It’ll make the previous attack look like nothing.”

Researchers at cybersecurity firm Wiz claim to have “spotted over 25,000 affected repositories across ~350 unique users, 1,000 new repositories are being added consistently every 30 minutes in the last couple of hours.” The company recommends “immediate investigation and remediation” for any environment using npm.


Risk Warning: this article represents only the author’s views and is for reference only. It does not constitute investment advice or financial guidance, nor does it represent the stance of the Markets.com platform.When considering shares, indices, forex (foreign exchange) and commodities for trading and price predictions, remember that trading CFDs involves a significant degree of risk and could result in capital loss.Past performance is not indicative of any future results. This information is provided for informative purposes only and should not be construed to be investment advice. Trading cryptocurrency CFDs and spread bets is restricted for all UK retail clients. 

Latest news

Sunday, 19 April 2026

Indices

Gold Price Today, April 20: Gold (XAUUSD) Slumps Below $4,800 on Renewed Strait of Hormuz Tensions

Sunday, 19 April 2026

Indices

Tesla (TSLA) Stock News: Tesla Faces $43.9 Billion Free Cash Flow Swing As 2026 Outlook Turns Negative

Thursday, 16 April 2026

Indices

Gold price today, April 17: XAUUSD climbs 3.6% amid oil volatility, how high will gold go in 2026?

Thursday, 16 April 2026

Indices

Crypto market update: Altcoin Season Index surges to 38, Altcoin price today (ALT/USD) is $0.000104

Thursday, 16 April 2026

Indices

Citi Warns of Twin Rate Hikes by SARB Amid Rising Oil Prices and Inflation Pressures

Thursday, 16 April 2026

Indices

Crypto Market News: South Korea Moves to Phase Out Government Cards in Favor of Blockchain Deposit Tokens

Wednesday, 15 April 2026

Indices

Middle East Financial News: Saudi Arabia Steps In with $3 Billion Aid for Pakistan as UAE Demands Debt Repayment

Wednesday, 15 April 2026

Indices

Gold price today, April 16: XAU/USD drifts below $4,800 as the US Dollar strengthens

Wednesday, 15 April 2026

Indices

How is the ZA economy doing right now: What is the current rate of unemployment in South Africa?

Wednesday, 15 April 2026

Indices

AI Industry Boom: What’s Driving the Allbirds ($BIRD) Stock Rally? Is Allbirds Inc the Next AI Giant?