SlowMist CISO: NPM Supply Chain Attack Latest Variant "Shai-Hulud 3.0" is Coming, Please Be Vigilant

By: theblockbeats.news|2025/12/29 12:16:14
0
Share
copy

BlockBeats News, December 29, SlowMist Chief Security Officer 23pds issued a security alert, the latest variant of the NPM supply chain attack "Shai-Hulud 3.0" strikes again. All projects and platforms are advised to be on high alert. Previously, the suspected Trust Wallet API key leak may have led to the Shai-Hulud 2.0 attack.

Shai-Hulud is a series of self-propagating worm-like supply chain attacks targeting the NPM ecosystem, aiming to steal developer credentials, cloud keys, and environment secrets. The latest variant (referred to by the community as Shai-Hulud 3.0 or a new strain) was discovered by Aikido Security researcher Charlie Eriksen on December 28, 2025. Currently, its spread is limited and may be in a testing phase.

-- Price

--

You may also like

Web3 is dead, Web2+3 should rise

We are not aiming to hold a self-indulgent party for Web3 practitioners, but rather to build a bridge for rational connection between Web2 and Web3.

Stablecoins and Latin American Remittances: The Misunderstood $174 Billion Market

In the Latin American remittance market, the real protagonists have never been the young people speculating on cryptocurrencies, but rather the 50-year-old workers who send money to their mothers every month. They don't care about blockchain; they only care about whether the money has arrived.

The arrival of the Web 3.0 era: A review of Hong Kong court rulings on digital assets

Hong Kong judiciary landmark: The court officially recognizes cryptocurrency as legal property and introduces the "tokenized injunction" to track and freeze involved funds, comprehensively upgrading the protection of digital asset investors.

Track Markets At a Glance: New WEEX Price Widgets for iOS & Android

To streamline your market data access, WEEX has officially launched "Market Watchlist" desktop widgets

The billion-dollar lesson: The focus of DeFi security is shifting from code to operational governance

Warning of nearly $1 billion loss in DeFi: Security pain points have shifted from code vulnerabilities to permissions and operations. Introducing TradFi bank-level risk control and AI defenses is the way to balance openness and security.

A Brief Analysis of Stablecoin Licenses and On-Chain Funding

Hong Kong accelerates the layout of digital finance, providing a panoramic analysis of the evolution of three major on-chain financial forms: central bank digital currency, deposit tokens, and stablecoins, along with future opportunities.

Contents

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com