Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Exclusive Binance’s SB Seker on India's INR Stablecoin Case, the USD Premium & Rebuilding Regulator Trust
    Exclusive: Binance’s SB Seker on India’s INR Stablecoin Case, the USD Premium & Rebuilding Regulator Trust
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    80% of Major SpaceX Investors Deal With Crypto
    80% of Major SpaceX Investors Deal With Crypto
    SEC Cancels Crypto Meeting Why Rulemaking Just Hit Another Wall
    SEC Cancels Crypto Meeting: Why Rulemaking Just Hit Another Wall
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It's Actually Doing
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It’s Actually Doing
  • Opinion
    OpinionShow More
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

Shai-Hulud Malware Hits 400+ NPM Packages, Including Crypto Libraries

Some firms, like OpenSea, protected themselves with strong security systems and avoided being affected by the attack.

Written By Iyiola Adrian
Fact Checked by Jahnu Jagtap
Published 2025-11-25·Updated 9 months ago
Make The Crypto Times preferred on GoogleGoogle
Shai-Hulud Malware Hits 400+ NPM Packages, Including Crypto Libraries

Key Highlights

  • Over 400 NPM packages, including several crypto-related ENS packages, were infected by the Shai-Hulud malware.
  • The malware steals credentials, spreads automatically, and can make private repositories public.
  • Some firms, like OpenSea, avoided the attack using preemptive security measures, while developers are updating and scanning packages.

A JavaScript supply-chain attack has hit over 400 NPM packages, including several used widely in cryptocurrency, researchers say. The malware, called Shai-Hulud, spreads automatically and steals credentials from developer systems. 

Charlie Eriksen of Aikido Security confirmed the infected packages in a today post and validated each detection to avoid false positives.

Crypto Packages in Danger

At least 10 of the affected packages are connected to the Ethereum Name Service (ENS). Some of these packages, like content-hash and address-encoder, receive tens of thousands of downloads every week. ENS packages like ensjs, ens-validation, ethereum-ens, and ens-contracts are also compromised. Another crypto package, crypto-addr-codec, was infected, with almost 35,000 downloads per week.

Non-crypto packages were affected too. Libraries from the automation platform Zapier saw tens of thousands of downloads weekly. Some packages reached over 70,000 downloads, and one popular library exceeded 1.5 million weekly downloads. 

Shai Hulud also compromised these packages:

– @ensdomains/ens-validation
– @ensdomains/content-hash
– ethereum-ens
– @ensdomains/react-ens-address
– @ensdomains/ens-contracts
– @ensdomains/ensjs
– @ensdomains/ens-archived-contracts
– @ensdomains/dnssecoraclejs@ensdomains

— Charlie Eriksen (@CharlieEriksen) November 24, 2025

Shai-Hulud is different from previous attacks. In September, hackers stole $50 million in crypto through NPM. This time, the malware spreads automatically and steals secrets from developer environments. Slava Demchuk, CEO of AMLBot, said, “Once a system is infected, the worm harvests secrets, replicates itself, makes private repositories public, and then continues to spread.”

How the Malware Works and Response

The malware infects through a deceptive preinstall script that downloads a large payload during installation. It posts stolen credentials to public GitHub repositories under the victim’s account. Using stolen NPM tokens, it spreads further across developer environments. Projects like PostHog libraries and ENS contracts have responded quickly, deprecating bad versions, rotating keys, and urging developers to revert to safe versions.

Some companies were protected. CTO of OpenSea, Chris Maddern confirmed that OpenSea was not affected, thanks to preemptive protection systems. 

gm

we have confirmed that @opensea is not affected by the ongoing npm package security incident

this was preemptively detected & prevented by sophisticated protection systems in place to secure code shipped to all opensea products

stay safe out there today 🤝 https://t.co/mwAECg7ccB

— Chris Maddern (@chrismaddern) November 24, 2025

ENS Labs also said their main website and names are safe. Packages published after 5:49 AM UTC on November 24, 2025, are under investigation. Developers are scanning lockfiles, tracking suspicious repos, and pinning versions to limit exposure.

We have identified that certain npm packages starting with @ensdomains published around 5:49am UTC today may be affected by a Sha1-Hulud supply-chain attack that has compromised over 400 NPM libraries, including several ENS packages.

The team has updated all latest tags and is…

— ens.eth (@ensdomains) November 24, 2025

Cybersecurity firm Wiz reported over 25,000 affected repositories across about 350 users, with 1,000 new repositories added every 30 minutes recently. The company urged “immediate investigation and remediation” for all NPM environments.

Also Read: Perpl Upgrades to Chainlink Data Streams on Monad

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

NVIDIA Posts $96.2B Q2 Revenue, Guides $108B Q3 as Bitcoin Miners Pivot to AI 
NVIDIA Posts $96.2B Q2 Revenue, Guides $108B Q3 as Bitcoin Miners Pivot to AI 
Bitcoin's First Quantum-Safe Transaction Is Live on Mainnet, No Soft Fork Needed
Bitcoin’s First Quantum-Safe Transaction Is Live on Mainnet, No Soft Fork Needed
Tokenized RWA Market Hits $44.7B as Funds Hold 76.4% Share
Tokenized RWA Market Hits $44.7B as Funds Hold 76.4% Share
Crypto Taxable Activity Tops $457B Globally in 2025: Chainalysis
Crypto Taxable Activity Tops $457B Globally in 2025: Chainalysis
Federal High Court headquarters in Abuja with police vehicle
Nigerian Court Grants $371K Bail in Alleged Crypto Investment Fraud

Find Us on Socials

You may also like

Bitcoin and Crypto Stocks Slide After Hot PCE Data

Bitcoin and Crypto Stocks Slide After Hot PCE Data

Silhouette of a person using a smartphone in front of large Digital Ruble symbol

Russian Telecom Firms Set to Accept Digital Ruble Payments

Roman Storm, Co-Founder of Tornado Cash

Tornado Cash Co-Founder Roman Storm’s Retrial Pushed to April 2027 Over Pending Motion

Hooded figure sitting in front of multiple screens showing code, facing a central display with the purple Enjin logo

Enjin Crypto Items Exploit Drains 5.24M ENJ From 52 Wallets

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information