Open account

Npm attack triggers 637 malware versions in 16 million downloads

A large-scale npm supply-chain attack — dubbed “Mini Shai-Hulud” — deployed 637 infected package versions across 323 packages in a 27‑minute burst, with weekly downloads topping ~16 million. The malware hides in IDEs and AI-assistants, exfiltrating AWS credentials and crypto wallet private keys via GitHub’s API, putting Web3 developers and on‑chain assets at acute risk. npm revoked detailed write-access keys and urged migration to Trusted Publishing, but security experts warn infections embedded in developer environments can persist. Market impact: heightened security concerns could weigh on developer confidence and on-chain activity, increase custodial risk for ETH holders, and raise the probability of wallet compromises or forced selling if keys are stolen. Investors should monitor disclosure of compromised projects, rotate keys, and treat the event as a bearish catalyst for short-term crypto sentiment and operational risk.

Category

Ethereum

Sentiment

Bearish

Event

Security incident

Reading time

1 min