Key Highlights
- Over 400 NPM packages, including several crypto-related ENS packages, were infected by the Shai-Hulud malware.
- The malware steals credentials, spreads automatically, and can make private repositories public.
- Some firms, like OpenSea, avoided the attack using preemptive security measures, while developers are updating and scanning packages.
A JavaScript supply-chain attack has hit over 400 NPM packages, including several used widely in cryptocurrency, researchers say. The malware, called Shai-Hulud, spreads automatically and steals credentials from developer systems.
Charlie Eriksen of Aikido Security confirmed the infected packages in a today post and validated each detection to avoid false positives.
Crypto Packages in Danger
At least 10 of the affected packages are connected to the Ethereum Name Service (ENS). Some of these packages, like content-hash and address-encoder, receive tens of thousands of downloads every week. ENS packages like ensjs, ens-validation, ethereum-ens, and ens-contracts are also compromised. Another crypto package, crypto-addr-codec, was infected, with almost 35,000 downloads per week.
Non-crypto packages were affected too. Libraries from the automation platform Zapier saw tens of thousands of downloads weekly. Some packages reached over 70,000 downloads, and one popular library exceeded 1.5 million weekly downloads.
Shai-Hulud is different from previous attacks. In September, hackers stole $50 million in crypto through NPM. This time, the malware spreads automatically and steals secrets from developer environments. Slava Demchuk, CEO of AMLBot, said, “Once a system is infected, the worm harvests secrets, replicates itself, makes private repositories public, and then continues to spread.”
How the Malware Works and Response
The malware infects through a deceptive preinstall script that downloads a large payload during installation. It posts stolen credentials to public GitHub repositories under the victim’s account. Using stolen NPM tokens, it spreads further across developer environments. Projects like PostHog libraries and ENS contracts have responded quickly, deprecating bad versions, rotating keys, and urging developers to revert to safe versions.
Some companies were protected. CTO of OpenSea, Chris Maddern confirmed that OpenSea was not affected, thanks to preemptive protection systems.
ENS Labs also said their main website and names are safe. Packages published after 5:49 AM UTC on November 24, 2025, are under investigation. Developers are scanning lockfiles, tracking suspicious repos, and pinning versions to limit exposure.
Cybersecurity firm Wiz reported over 25,000 affected repositories across about 350 users, with 1,000 new repositories added every 30 minutes recently. The company urged “immediate investigation and remediation” for all NPM environments.
Also Read: Perpl Upgrades to Chainlink Data Streams on Monad
