Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
  • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

Shai-Hulud Malware Hits 400+ NPM Packages, Including Crypto Libraries

Some firms, like OpenSea, protected themselves with strong security systems and avoided being affected by the attack.

Written By Iyiola Adrian
Fact Checked by Jahnu Jagtap
Published November 25, 2025 2:15 AM·Updated 9 months ago
Make The Crypto Times preferred on GoogleGoogle
Shai-Hulud Malware Hits 400+ NPM Packages, Including Crypto Libraries

Key Highlights

  • Over 400 NPM packages, including several crypto-related ENS packages, were infected by the Shai-Hulud malware.
  • The malware steals credentials, spreads automatically, and can make private repositories public.
  • Some firms, like OpenSea, avoided the attack using preemptive security measures, while developers are updating and scanning packages.

A JavaScript supply-chain attack has hit over 400 NPM packages, including several used widely in cryptocurrency, researchers say. The malware, called Shai-Hulud, spreads automatically and steals credentials from developer systems. 

Charlie Eriksen of Aikido Security confirmed the infected packages in a today post and validated each detection to avoid false positives.

Crypto Packages in Danger

At least 10 of the affected packages are connected to the Ethereum Name Service (ENS). Some of these packages, like content-hash and address-encoder, receive tens of thousands of downloads every week. ENS packages like ensjs, ens-validation, ethereum-ens, and ens-contracts are also compromised. Another crypto package, crypto-addr-codec, was infected, with almost 35,000 downloads per week.

Non-crypto packages were affected too. Libraries from the automation platform Zapier saw tens of thousands of downloads weekly. Some packages reached over 70,000 downloads, and one popular library exceeded 1.5 million weekly downloads. 

Shai Hulud also compromised these packages:

– @ensdomains/ens-validation
– @ensdomains/content-hash
– ethereum-ens
– @ensdomains/react-ens-address
– @ensdomains/ens-contracts
– @ensdomains/ensjs
– @ensdomains/ens-archived-contracts
– @ensdomains/dnssecoraclejs@ensdomains

— Charlie Eriksen (@CharlieEriksen) November 24, 2025

Shai-Hulud is different from previous attacks. In September, hackers stole $50 million in crypto through NPM. This time, the malware spreads automatically and steals secrets from developer environments. Slava Demchuk, CEO of AMLBot, said, “Once a system is infected, the worm harvests secrets, replicates itself, makes private repositories public, and then continues to spread.”

How the Malware Works and Response

The malware infects through a deceptive preinstall script that downloads a large payload during installation. It posts stolen credentials to public GitHub repositories under the victim’s account. Using stolen NPM tokens, it spreads further across developer environments. Projects like PostHog libraries and ENS contracts have responded quickly, deprecating bad versions, rotating keys, and urging developers to revert to safe versions.

Some companies were protected. CTO of OpenSea, Chris Maddern confirmed that OpenSea was not affected, thanks to preemptive protection systems. 

gm

we have confirmed that @opensea is not affected by the ongoing npm package security incident

this was preemptively detected & prevented by sophisticated protection systems in place to secure code shipped to all opensea products

stay safe out there today 🤝 https://t.co/mwAECg7ccB

— Chris Maddern (@chrismaddern) November 24, 2025

ENS Labs also said their main website and names are safe. Packages published after 5:49 AM UTC on November 24, 2025, are under investigation. Developers are scanning lockfiles, tracking suspicious repos, and pinning versions to limit exposure.

We have identified that certain npm packages starting with @ensdomains published around 5:49am UTC today may be affected by a Sha1-Hulud supply-chain attack that has compromised over 400 NPM libraries, including several ENS packages.

The team has updated all latest tags and is…

— ens.eth (@ensdomains) November 24, 2025

Cybersecurity firm Wiz reported over 25,000 affected repositories across about 350 users, with 1,000 new repositories added every 30 minutes recently. The company urged “immediate investigation and remediation” for all NPM environments.

Also Read: Perpl Upgrades to Chainlink Data Streams on Monad

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

Crypto Market Live: LAB Token Collapses 85% to $2

Prediction Market Fight May Reach Supreme Court CFTC Chair Selig

Prediction Market Fight May Reach Supreme Court: CFTC Chair Selig

Anchorage Bets Big on AI Economy With New Banking Model

Anchorage Bets Big on AI Economy With New Banking Model

Tapnob Rolls Out Crypto-to-Naira Payment Platform in Nigeria

Tapnob Rolls Out Crypto-to-Naira Payment Platform in Nigeria

Clarity Act on Fast Track Senator Moreno Sets July 4 Deadline

Clarity Act on Fast Track? Senator Moreno Sets July 4 Deadline

Find Us on Socials

You may also like

Crypto Market Today Utya, Dogs, LAB Top Gainers as Bitcoin Reclaims $81K

Crypto Market Today: Utya, Dogs, LAB Top Gainers as Bitcoin Reclaims $81K

Rep. Horsford Says Crypto Tax Bill Is Foundation as CLARITY Stalls

Rep. Horsford Says Crypto Tax Bill Is Foundation as CLARITY Stalls

$295M Hack Fallout: Drift Protocol Rolls Out User Recovery Plan

$295M Hack Fallout: Drift Protocol Rolls Out User Recovery Plan

Just 0.1% of Polymarket accounts captured 67% of all profits WSJ

Just 0.1% of Polymarket accounts captured 67% of all profits: WSJ

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information