• bitcoinBitcoin (BTC) $ 90,402.00
  • ethereumEthereum (ETH) $ 3,080.02
  • tetherTether (USDT) $ 0.998795
  • xrpXRP (XRP) $ 2.09
  • bnbBNB (BNB) $ 904.33
  • solanaSolana (SOL) $ 135.50
  • usd-coinUSDC (USDC) $ 1.00
  • tronTRON (TRX) $ 0.300893
  • staked-etherLido Staked Ether (STETH) $ 3,078.18
  • dogecoinDogecoin (DOGE) $ 0.139289
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.00
  • cardanoCardano (ADA) $ 0.386348
  • bitcoin-cashBitcoin Cash (BCH) $ 643.83
  • wrapped-stethWrapped stETH (WSTETH) $ 3,767.54
  • whitebitWhiteBIT Coin (WBT) $ 54.95
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,346.61
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 90,146.00
  • wrapped-eethWrapped eETH (WEETH) $ 3,340.70
  • usdsUSDS (USDS) $ 0.999606
  • chainlinkChainlink (LINK) $ 13.11
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998685
  • moneroMonero (XMR) $ 469.16
  • leo-tokenLEO Token (LEO) $ 9.05
  • wethWETH (WETH) $ 3,077.87
  • stellarStellar (XLM) $ 0.225681
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 90,325.00
  • suiSui (SUI) $ 1.78
  • ethena-usdeEthena USDe (USDE) $ 0.998908
  • litecoinLitecoin (LTC) $ 81.02
  • zcashZcash (ZEC) $ 369.82
  • avalanche-2Avalanche (AVAX) $ 13.70
  • hyperliquidHyperliquid (HYPE) $ 23.91
  • shiba-inuShiba Inu (SHIB) $ 0.000009
  • hedera-hashgraphHedera (HBAR) $ 0.117609
  • canton-networkCanton (CC) $ 0.129882
  • usdt0USDT0 (USDT0) $ 0.998707
  • susdssUSDS (SUSDS) $ 1.08
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.167056
  • daiDai (DAI) $ 0.999367
  • the-open-networkToncoin (TON) $ 1.74
  • crypto-com-chainCronos (CRO) $ 0.100326
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • paypal-usdPayPal USD (PYUSD) $ 0.999597
  • uniswapUniswap (UNI) $ 5.46
  • polkadotPolkadot (DOT) $ 2.09
  • usd1-wlfiUSD1 (USD1) $ 0.999446
  • mantleMantle (MNT) $ 0.976598
  • rainRain (RAIN) $ 0.008991
  • memecoreMemeCore (M) $ 1.74
  • bittensorBittensor (TAO) $ 278.33
  • aaveAave (AAVE) $ 164.27
  • pepePepe (PEPE) $ 0.000006
  • bitget-tokenBitget Token (BGB) $ 3.50
  • tether-goldTether Gold (XAUT) $ 4,499.19
  • okbOKB (OKB) $ 109.80
  • nearNEAR Protocol (NEAR) $ 1.69
  • falcon-financeFalcon USD (USDF) $ 0.993520
  • jito-staked-solJito Staked SOL (JITOSOL) $ 169.89
  • ethereum-classicEthereum Classic (ETC) $ 12.51
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.176757
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,078.93
  • ethenaEthena (ENA) $ 0.226639
  • pi-networkPi Network (PI) $ 0.208305
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • internet-computerInternet Computer (ICP) $ 3.17
  • pax-goldPAX Gold (PAXG) $ 4,510.80
  • aster-2Aster (ASTER) $ 0.717635
  • htx-daoHTX DAO (HTX) $ 0.000002
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.72
  • worldcoin-wldWorldcoin (WLD) $ 0.569882
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • global-dollarGlobal Dollar (USDG) $ 0.999624
  • binance-staked-solBinance Staked SOL (BNSOL) $ 148.05
  • kucoin-sharesKuCoin (KCS) $ 10.82
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • ripple-usdRipple USD (RLUSD) $ 0.999524
  • aptosAptos (APT) $ 1.81
  • skySky (SKY) $ 0.058449
  • pump-funPump.fun (PUMP) $ 0.002268
  • bfusdBFUSD (BFUSD) $ 0.998488
  • wbnbWrapped BNB (WBNB) $ 904.26
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999703
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,553.29
  • hash-2Provenance Blockchain (HASH) $ 0.023689
  • ondo-financeOndo (ONDO) $ 0.398317
  • cosmosCosmos Hub (ATOM) $ 2.56
  • kaspaKaspa (KAS) $ 0.046117
  • arbitrumArbitrum (ARB) $ 0.206583
  • gatechain-tokenGate (GT) $ 10.24
  • algorandAlgorand (ALGO) $ 0.133375
  • render-tokenRender (RENDER) $ 2.26
  • midnight-3Midnight (NIGHT) $ 0.069798
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,267.03
  • filecoinFilecoin (FIL) $ 1.48
  • official-trumpOfficial Trump (TRUMP) $ 5.40
  • quant-networkQuant (QNT) $ 74.00
  • bridged-wrapped-lido-staked-ether-scrollBridged Wrapped Lido Staked Ether (Scroll) (WSTETH) $ 3,757.08
  • vechainVeChain (VET) $ 0.011668
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 90,523.00
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 90,259.00
  • ignition-fbtcFunction FBTC (FBTC) $ 89,964.00
  • nexoNEXO (NEXO) $ 0.963604
  • flare-networksFlare (FLR) $ 0.011248
  • myx-financeMYX Finance (MYX) $ 4.91
  • xdce-crowd-saleXDC Network (XDC) $ 0.048540
  • bonkBonk (BONK) $ 0.000011
  • usddUSDD (USDD) $ 0.998560
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • usdtbUSDtb (USDTB) $ 0.999414
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,276.80
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,333.66
  • ousgOUSG (OUSG) $ 113.92
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.95
  • sei-networkSei (SEI) $ 0.119797
  • wrappedm-by-m0WrappedM by M^0 (WM) $ 0.995130
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.011820
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999717
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 90,196.00
  • blockstackStacks (STX) $ 0.387174
  • clbtcclBTC (CLBTC) $ 90,541.00
  • morphoMorpho (MORPHO) $ 1.29
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,288.06
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.06
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.05
  • story-2Story (IP) $ 2.01
  • beldexBeldex (BDX) $ 0.088675
  • jupiter-exchange-solanaJupiter (JUP) $ 0.207767
  • usdaiUSDai (USDAI) $ 1.00
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 157.34
  • wrapped-flareWrapped Flare (WFLR) $ 0.011245
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.279282
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,078.93
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,258.78
  • lighterLighter (LIT) $ 2.55
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999848
  • tezosTezos (XTZ) $ 0.579700
  • optimismOptimism (OP) $ 0.316764
  • curve-dao-tokenCurve DAO (CRV) $ 0.406500
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • usual-usdUsual USD (USD0) $ 0.996774
  • c8ntinuumc8ntinuum (CTM) $ 0.125497
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,077.86
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 24.12
  • tbtctBTC (TBTC) $ 90,327.00
  • lido-daoLido DAO (LDO) $ 0.629920
  • spx6900SPX6900 (SPX) $ 0.573264
  • chilizChiliz (CHZ) $ 0.050298
  • injective-protocolInjective (INJ) $ 5.17
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998735
  • flokiFLOKI (FLOKI) $ 0.000051
  • ghoGHO (GHO) $ 0.999314
  • true-usdTrueUSD (TUSD) $ 0.997301
  • gtethGTETH (GTETH) $ 3,077.63
  • aerodrome-financeAerodrome Finance (AERO) $ 0.535148
  • ether-fiEther.fi (ETHFI) $ 0.730315
  • fasttokenFasttoken (FTN) $ 1.09
  • celestiaCelestia (TIA) $ 0.545128
  • msolMarinade Staked SOL (MSOL) $ 183.00
  • dashDash (DASH) $ 36.96
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • syrupMaple Finance (SYRUP) $ 0.392868
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,324.50
  • stader-ethxStader ETHx (ETHX) $ 3,317.91
  • the-graphThe Graph (GRT) $ 0.041467
  • newton-projectAB (AB) $ 0.004485
  • iotaIOTA (IOTA) $ 0.100913
  • jasmycoinJasmyCoin (JASMY) $ 0.008580
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.210683
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,449.54
  • bittorrentBitTorrent (BTT) $ 0.00000042
  • sbtc-2sBTC (SBTC) $ 91,210.00
  • starknetStarknet (STRK) $ 0.081453
  • justJUST (JST) $ 0.040997
  • pippinpippin (PIPPIN) $ 0.404524
  • usdbUSDB (USDB) $ 0.994121
  • staked-aaveStaked Aave (STKAAVE) $ 162.63
  • doublezeroDoubleZero (2Z) $ 0.115103
  • ethereum-name-serviceEthereum Name Service (ENS) $ 10.38
  • sun-tokenSun Token (SUN) $ 0.020609
  • conflux-tokenConflux (CFX) $ 0.076282
  • pyth-networkPyth Network (PYTH) $ 0.067187
  • bitcoin-svBitcoin SV (BSV) $ 19.26
  • dogwifcoindogwifhat (WIF) $ 0.376626
  • kaiaKaia (KAIA) $ 0.063996
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.883137
  • apenftAINFT (NFT) $ 0.00000037
  • gnosisGnosis (GNO) $ 137.96
  • fartcoinFartcoin (FARTCOIN) $ 0.364895
  • wrapped-stx-velarWrapped STX (Velar) (WSTX) $ 0.359830
  • crvusdcrvUSD (CRVUSD) $ 0.999664
  • euro-coinEURC (EURC) $ 1.16
  • cap-usdCap USD (CUSD) $ 0.993536
  • chain-2Onyxcoin (XCN) $ 0.008404
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.139312
  • olympusOlympus (OHM) $ 21.64
  • telcoinTelcoin (TEL) $ 0.003706
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 90,361.00
  • pendlePendle (PENDLE) $ 2.06

New NPM supply-chain attack compromises major ENS and crypto libraries

0 30

New NPM supply-chain attack compromises major ENS and crypto libraries

A major JavaScript supply-chain attack has compromised hundreds of software packages — including at least 10 used widely across the crypto ecosystem — according to new research from cybersecurity firm Aikido Security.

In a Monday post, Charlie Eriksen, a researcher at Aikido Security, shared the names of over 400 packages that show signs of infection with the “Shai Hulud” self-replicating malware used in an ongoing JavaScript NPM library supply chain attack. Eriksen said he validated each detection to avoid false positives.

Many of the cryptocurrency-related packages involved receive tens of thousands of downloads per week and have numerous other packages that require them to function. In an X post published earlier today, Eriksen also warned the Ethereum Name Service (ENS) team that several of their packages are affected.

New NPM supply-chain attack compromises major ENS and crypto libraries

Source: Charlie Eriksen

Shai Hulud is part of a broader supply chain attack trend. In Early September, the largest NPM attack reported to date saw hackers only steal $50 million of crypto. Amazon Web Services noted that this first attack was followed by the Shai-Hulud worm spreading autonomously just a week later.

While the previous attack directly targeted crypto to steal assets, Shai-Hulud is a general-purpose credential-stealing malware that spreads autonomously across developer infrastructure. If the infected environment contains wallet keys, the malware will steal them as “secrets” like any other credential.

Related: Failed NPM exploit highlights looming threat to crypto security: Exec

Which crypto packages are affected?

Among all the affected packages, at least 10 were specifically related to the cryptocurrency industry, and nearly all were tied to the ENS, a human-readable address name service. Among the affected packages are ENS’s content-hash, with almost 36,000 weekly downloads, and 91 software packages depending on it, as well as address-encoder, with over 37,500 weekly downloads.

Other ENS packages affected include ensjs (over 30,000 weekly downloads), ens-validation (1,750 weekly downloads), ethereum-ens (12,650 weekly downloads), and ens-contracts (nearly 3,100 weekly downloads). A cryptocurrency-related package unrelated to ENS, called crypto-addr-codec, was also compromised, with almost 35,000 downloads.

Related: $27 million gone, no private keys exposed: How the BigONE hack happened

Popular non-crypto packages affected

Non-crypto-related packages affected include some offered by the corporate automation platform Zapier, including one with over 40,000 downloads per week and many not far behind. In a subsequent post, Eriksen pointed to other packages that were infected, some with nearly 70,000 weekly downloads, and to another package seeing well over 1.5 million weekly downloads.

“The scope of this new Shai Hulud attack is frankly massive; we’re still working through the queue to confirm it all,” Eriksen wrote on X.

“It’ll make the previous attack look like nothing.“

Researchers at cybersecurity firm Wiz claim to have “spotted over 25,000 affected repositories across ~350 unique users, 1,000 new repositories are being added consistently every 30 minutes in the last couple of hours.” The company recommends “immediate investigation and remediation” for any environment using npm.

Magazine: ‘Help! My robot vac is stealing my Bitcoin’: When smart devices attack

Source

Leave A Reply

Your email address will not be published.