COINTURK NEWSCOINTURK NEWSCOINTURK NEWS
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Search
© 2024 COINTURK NEWS. All Rights Reserved.
Reading: Npm attack triggers 637 malware versions in 16 million downloads
Share
Font ResizerAa
COINTURK NEWSCOINTURK NEWS
Font ResizerAa
Search
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Follow US
© 2025 >> COINTURK NEWS
Powered by LK SOFTWARE
COINTURK NEWS > Cryptocurrency News > Npm attack triggers 637 malware versions in 16 million downloads
Cryptocurrency News

Npm attack triggers 637 malware versions in 16 million downloads

In Brief

  • 🚨 Attackers uploaded 637 malware versions to npm, downloaded 16 million times.

  • Access keys were revoked after widespread “Mini Shai-Hulud” malware infection in $ETH projects.

  • 🛡️ Critical data: Compromised npm account enabled massive supply chain breach in minutes.

İlayda Peker
İlayda Peker 2 hours ago
Share
SHARE

After a lengthy period of silence, npm’s registry administrators have launched emergency actions following a large-scale supply chain attack. By revoking detailed access keys with write permissions, the team aims to stop hackers from bypassing two-factor authentication. This move is intended to stem the fifth wave of the malicious software outbreak known as “Mini Shai-Hulud,” which has rapidly impacted Web3 developers.

Contents
Urgent call to action from npmSecurity experts voice concernThe “Mini Shai-Hulud” malware and its impactScale and reach of the attack

Urgent call to action from npm

Amid an escalating security crisis, npm has issued an urgent alert to its users. Developers are being advised to immediately replace all existing secret keys and to migrate to the more secure Trusted Publishing method. These steps are designed to ensure compromised projects can be rapidly secured and cleansed of malware.

Security experts voice concern

However, cybersecurity professionals have criticized npm’s response as insufficient. Many researchers believe the measures only address surface-level symptoms, ignoring deeper vulnerabilities. Taylor Monahan, a security researcher at MetaMask, described npm’s delayed reaction as an admission of a fundamental infrastructure crisis. Another expert, Moshe Siman Tov Bustan, stressed that merely restricting access cannot halt malware proliferation and called for thorough technical analysis.

According to security researchers, revoking access keys may block new malware versions but fails to protect developers whose IDEs are already infected with “Mini Shai-Hulud.” Once embedded in a developer’s system, the spyware continues to steal sensitive data quietly, even if npm disables access on its end.

Mini glossary: npm is a central repository for open source packages widely used in JavaScript projects. Developers easily integrate these packages into their work. A supply-chain attack targets systems by compromising third-party code or services, often causing widespread impact.

The “Mini Shai-Hulud” malware and its impact

The latest wave stands out due to the malware’s ability to adapt to developers’ daily workflows. After infiltrating a system, it does more than harvest data: it hides within artificial intelligence assistants and IDE tool configurations. As a result, every time the developer runs an AI tool, the malware is reactivated without detection.

Even if a developer removes infected files or cleanses the system, relaunching an AI assistant can trigger a new infection. All valuable information—including AWS cloud credentials and crypto wallet private keys—is exfiltrated in encrypted form through GitHub’s official API. For security tools, this malicious activity is disguised as ordinary code uploads by legitimate developers.

Scale and reach of the attack

The recent attack wave peaked when the legitimate npm account “atool” was compromised. In just 27 minutes, automated software deployed a total of 637 infected versions across 323 distinct packages. The weekly download count for these packages has topped approximately 16 million.

Package NameNumber of Infected VersionsApproximate Weekly Downloads
atool63716,000,000

This incident has exposed major weaknesses in dependency-based ecosystems and reinforced the critical role of supply chain security. Experts are urging users to adopt more modern and secure access methods to protect their projects moving forward.

The sheer scale at which attackers gained access demonstrates the vulnerabilities within widely trusted packages and the urgent need for robust defense mechanisms across the software supply chain.

The npm team’s decision to revoke access keys is only a temporary measure, and more comprehensive investigations are necessary to prevent future incidents at this scale.

While access restrictions may slow the spread of new malware versions, developers must remain vigilant and adopt advanced security practices to protect their environments.

This attack highlights the evolving tactics of cybercriminals targeting the software ecosystem’s weakest links, putting millions of users and valuable assets at risk.

You can follow our news on Telegram, Facebook & Coinmarketcap & X
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

You Might Also Like

Nobitex transfers $2.3 billion via TRON and BNB Chain

Bitcoin tops $77,000 as long-term holders boost recovery

Ripple Prime joins EDX for $11.5 trillion crypto access

Over 3,800 GitHub code repositories breached in TeamPCP hack

Bankr halts swaps after $440,000 AI exploit hits users

İlayda Peker 20 May, 2026 - 6:27 pm 20 May, 2026 - 6:27 pm
Share This Article
Facebook Twitter
Share
İlayda Peker
By İlayda Peker
Follow:
Uluslararası İlişkiler ve Siyaset Bilimi Mezunu, Kitap sever.
Previous Article BTC and ETH reach 6.4 percent adoption in Poland
Next Article Nobitex transfers $2.3 billion via TRON and BNB Chain
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

8.1k Like
21.1k Follow
1.1k Follow

Latest News

Kraken and Coinbase hacks cost user $6.7 million in ETH, BTC
Coinbase
Babylon unveils trustless BTC DeFi vault, testnet set for May
Bitcoin (BTC)
Shibarium daily transactions jump 44 percent to 1,260
Shiba (SHIB)
//

COINTURK was launched in March 2014 by a group of technology enthusiasts who believe that Bitcoin will be as important as the internet in the world of the future thanks to the amazing technology underlying it.

CRYPTOCURRENCY LIVE PRICES

  • Bitcoin (BTC) Live Price
  • Ethereum (ETH) Live Price
  • Ripple (XRP) Live Price
  • Solana (SOL) Live Price
  • Dogecoin (DOGE) Live Price
  • Cardano (ADA) Live Price
  • Chainlink (LINK) Live Price

OUR PARTNERS

  • COINMARKETCAP
  • COINGECKO
  • BITCOINHABER
  • BH NEWS
  • 21MILYON
  • NEWSLINKER

OUR COMPANY

  • About Us
  • Cookie Policy
  • Advertising
  • Contact
COINTURK NEWSCOINTURK NEWS
Follow US
COINTURK NEWS 2026
Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Lost your password?