header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

SlowMist CISO: NPM Supply Chain Attack Latest Variant "Shai-Hulud 3.0" is Coming, Please Be Vigilant

2025-12-29 04:04

BlockBeats News, December 29, SlowMist Chief Security Officer 23pds issued a security alert, the latest variant of the NPM supply chain attack "Shai-Hulud 3.0" strikes again. All projects and platforms are advised to be on high alert. Previously, the suspected Trust Wallet API key leak may have led to the Shai-Hulud 2.0 attack.


Shai-Hulud is a series of self-propagating worm-like supply chain attacks targeting the NPM ecosystem, aiming to steal developer credentials, cloud keys, and environment secrets. The latest variant (referred to by the community as Shai-Hulud 3.0 or a new strain) was discovered by Aikido Security researcher Charlie Eriksen on December 28, 2025. Currently, its spread is limited and may be in a testing phase.

举报 Correction/Report
Correction/Report
Submit
Add Library
Visible to myself only
Public
Save
Choose Library
Add Library
Cancel
Finish