Bitmime
You have not selected any currencies to display
  • Bitmime – Bitcoin, Ethereum, Crypto News and Market Analysis
  • Cryptocurrency
    • Crypto Mining
  • Bitcoin
  • Ethereum
  • DeFi
  • Blockchain
  • Metaverse
No Result
View All Result
  • Bitmime – Bitcoin, Ethereum, Crypto News and Market Analysis
  • Cryptocurrency
    • Crypto Mining
  • Bitcoin
  • Ethereum
  • DeFi
  • Blockchain
  • Metaverse
No Result
View All Result
Bitmime
No Result
View All Result
Home Cryptocurrency

Malicious worm compromises crypto domains in supply-chain assault

Martin Spielberg by Martin Spielberg
November 25, 2025
in Cryptocurrency
0
Malicious worm compromises crypto domains in supply-chain assault
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Related articles

Bitcoin dominance dips to 23.6 fib degree, indicators potential altcoin rotation

Bitcoin dominance dips to 23.6 fib degree, indicators potential altcoin rotation

November 28, 2025
Bitcoin is redrawing the place cities and knowledge facilities rise because it competes for wasted vitality, not low cost labor

Bitcoin is redrawing the place cities and knowledge facilities rise because it competes for wasted vitality, not low cost labor

November 28, 2025



On Nov. 24, safety agency Aikido detected a second wave of the Shai-Hulud self-replicating npm worm, compromising 492 packages with a mixed 132 million month-to-month downloads.

The assault struck main ecosystems, together with AsyncAPI, PostHog, Postman, Zapier, and ENS, exploiting the ultimate weeks earlier than npm’s Dec. 9 deadline to revoke legacy authentication tokens.

Aikido’s triage queue flagged the intrusion round 3:16 AM UTC, as malicious variations of AsyncAPI’s go-template and 36 associated packages started spreading throughout the registry.

The attacker labeled stolen-credential repositories with the outline “Sha1-Hulud: The Second Coming,” sustaining theatrical branding from the September marketing campaign.

The worm installs the Bun runtime throughout bundle setup, then executes malicious code that searches developer environments for uncovered secrets and techniques utilizing TruffleHog.

Compromised API keys, GitHub tokens, and npm credentials are printed to randomly named public repositories, and the malware makes an attempt to propagate by pushing new contaminated variations to as much as 100 further packages, 5 instances the dimensions of the September assault.

Technical evolution and damaging payload

The November iteration introduces a number of modifications from the September assault.
The malware now creates repositories with randomly generated names for stolen information reasonably than utilizing hardcoded names, complicating takedown efforts.

Setup code installs Bun by way of setup_bun.js earlier than executing the first payload in bun_environment.js, which accommodates the worm logic and credential-exfiltration routines.

Essentially the most damaging addition: if the malware can not authenticate with GitHub or npm utilizing stolen credentials, it wipes all information within the consumer’s residence listing.

Aikido’s evaluation revealed execution errors that restricted the assault’s unfold. The bundling code that copies the total worm into new packages typically fails to incorporate bun_environment.js, leaving solely the Bun set up script with out the malicious payload.

Regardless of these failures, the preliminary compromises hit high-value targets with huge downstream publicity.

AsyncAPI packages dominated the primary wave, with 36 compromised releases together with @asyncapi/cli, @asyncapi/parser, and @asyncapi/generator.

PostHog adopted at 4:11 AM UTC, with contaminated variations of posthog-js, posthog-node, and dozens of plugins. Postman packages arrived at 5:09 AM UTC.

The Zapier compromise affected @zapier/zapier-sdk, zapier-platform-cli, and zapier-platform-core, whereas the ENS compromise affected @ensdomains/ensjs, @ensdomains/ens-contracts, and ethereum-ens.

GitHub department creation suggests repository-level entry

The AsyncAPI workforce found a malicious department of their CLI repository created instantly earlier than the compromised packages appeared on npm.

The department contained a deployed model of the Shai-Hulud malware, indicating the attacker gained write entry to the repository itself reasonably than merely hijacking npm tokens.

This escalation mirrors the method used within the authentic Nx compromise, wherein attackers modified supply repositories to inject malicious code into professional construct pipelines.

Aikido estimates that 26,300 GitHub repositories now comprise stolen credentials marked with the “Sha1-Hulud: The Second Coming” description.

The repositories comprise secrets and techniques uncovered by developer environments that ran the compromised packages, together with cloud service credentials, CI/CD tokens, and authentication keys for third-party APIs.

The general public nature of the leaks amplifies the harm: any attacker monitoring the repositories can harvest credentials in actual time and launch secondary assaults.

Assault timing and mitigation

The timing coincides with npm’s Nov. 15 announcement that it’ll revoke traditional authentication tokens on Dec. 9.

The attacker’s option to launch a last large-scale marketing campaign earlier than the deadline suggests they acknowledged the window for token-based compromises was closing. Aikido’s timeline exhibits the primary Shai-Hulud wave started Sept. 16.

The Nov. 24 “Second Coming” represents the attacker’s final alternative to use legacy tokens earlier than npm’s migration cuts off that entry.

Aikido recommends that safety groups audit all dependencies from affected ecosystems, significantly the Zapier, ENS, AsyncAPI, PostHog, and Postman packages put in or up to date after Nov. 24.

Organizations ought to rotate all GitHub, npm, cloud, and CI/CD secrets and techniques utilized in environments the place these packages have been current, and search GitHub for repositories with the “Sha1-Hulud: The Second Coming” description to find out if inside credentials have been uncovered.

Disabling npm postinstall scripts in CI pipelines prevents future install-time execution, and pinning bundle variations with lock information limits publicity to newly compromised releases.

Tags: attackcompromisesCryptodomainsMalicioussupplychainworm
Share76Tweet47

Related Posts

Bitcoin dominance dips to 23.6 fib degree, indicators potential altcoin rotation

Bitcoin dominance dips to 23.6 fib degree, indicators potential altcoin rotation

by Martin Spielberg
November 28, 2025
0

Key Takeaways Bitcoin dominance has retreated to the 23.6 % Fibonacci degree after a gradual multi week decline. Decrease dominance...

Bitcoin is redrawing the place cities and knowledge facilities rise because it competes for wasted vitality, not low cost labor

Bitcoin is redrawing the place cities and knowledge facilities rise because it competes for wasted vitality, not low cost labor

by Martin Spielberg
November 28, 2025
0

For 2 centuries, factories chased low cost arms and dense ports. Right now, miners roll into windy plateaus and hydro...

Huge Solana (SOL) Transfer Forward? Watch This Essential Degree

Huge Solana (SOL) Transfer Forward? Watch This Essential Degree

by Martin Spielberg
November 28, 2025
0

Solana reclaims $130 help. Analysts watch $250–$2,000 targets, NUPL knowledge alerts capitulation, and institutional curiosity grows. Solana (SOL) has...

GAME2 is accessible for buying and selling!

GAME2 is accessible for buying and selling!

by Martin Spielberg
November 27, 2025
0

We’re thrilled to announce that GAME2 is accessible for buying and selling on Kraken! Funding and buying and selling GAME2...

How Crypto Alternate Upbit Bought Robbed Once more – Six Years Later, Identical Date

How Crypto Alternate Upbit Bought Robbed Once more – Six Years Later, Identical Date

by Martin Spielberg
November 27, 2025
0

Upbit, South Korea's dominant cryptocurrency trade, suffered unauthorized withdrawals totaling roughly $36.9 million (54 billion received) early Thursday morning, marking...

Load More
  • Trending
  • Comments
  • Latest
Alchemy Quietly Buys NFT Launchpad HeyMint – Right here’s Extra data

Alchemy Quietly Buys NFT Launchpad HeyMint – Right here’s Extra data

May 25, 2025
BitHub 77-Bit token airdrop information

BitHub 77-Bit token airdrop information

January 15, 2025
Volatility Shares debuts first 1x XRP futures ETF for US buyers

Volatility Shares debuts first 1x XRP futures ETF for US buyers

May 26, 2025
Texas football’s rivalry matchup with Texas A&M

Texas football’s rivalry matchup with Texas A&M

May 9, 2025
6 Methods Web3 Is Altering On-line Communities

6 Methods Web3 Is Altering On-line Communities

1
Dogecoin (DOGE) Eyes $0.50 Once more: Is a New Rally on the Horizon?

Dogecoin (DOGE) Eyes $0.50 Once more: Is a New Rally on the Horizon?

0
Binance Pool Introduces Merged Mining with Fractal Bitcoin (FB) Rewards

Binance Pool Introduces Merged Mining with Fractal Bitcoin (FB) Rewards

0
Are Retail Buyers Behind The Bitcoin Worth Surge This Bull Run?

Are Retail Buyers Behind The Bitcoin Worth Surge This Bull Run?

0
Solana Worth Up 3% Regardless of $38M Upbit Hack

Solana Worth Up 3% Regardless of $38M Upbit Hack

November 28, 2025
How Web3 Gaming Infrastructure Grew to become the Prime Funding Precedence in 2025

How Web3 Gaming Infrastructure Grew to become the Prime Funding Precedence in 2025

November 28, 2025
Bitcoin dominance dips to 23.6 fib degree, indicators potential altcoin rotation

Bitcoin dominance dips to 23.6 fib degree, indicators potential altcoin rotation

November 28, 2025
Bitcoin Value Up 4% On Price Lower Hopes As SpaceX Strikes BTC

Bitcoin Value Up 4% On Price Lower Hopes As SpaceX Strikes BTC

November 28, 2025

About Us

Welcome to Bitmime.com, your go-to destination for the latest and most reliable news from the world of cryptocurrency, blockchain, and decentralized finance.

Categories

  • Bitcoin
  • Blockchain
  • Crypto Mining
  • Cryptocurrency
  • DeFi
  • Ethereum
  • Metaverse
  • Uncategorized

Recent Posts

  • Solana Worth Up 3% Regardless of $38M Upbit Hack
  • How Web3 Gaming Infrastructure Grew to become the Prime Funding Precedence in 2025
  • Bitcoin dominance dips to 23.6 fib degree, indicators potential altcoin rotation
  • Bitmime – Bitcoin, Ethereum, Crypto News and Market Analysis
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions

© 2024 bitmime.com. All rights reserved.

No Result
View All Result
  • Bitmime – Bitcoin, Ethereum, Crypto News and Market Analysis
  • Cryptocurrency
    • Crypto Mining
  • Bitcoin
  • Ethereum
  • DeFi
  • Blockchain
  • Metaverse

© 2024 bitmime.com. All rights reserved.