Over 400 npm code libraries, including Ethereum Name Service packages, were compromised in a supply chain cyberattack detected Nov. 24. ENS Labs reports user assets and domains remain unaffected. The post ENS Npm Packages Compromised in Supply Chain Cyberattack Affecting 400 Libraries appeared first on Coinspeaker.Over 400 npm code libraries, including Ethereum Name Service packages, were compromised in a supply chain cyberattack detected Nov. 24. ENS Labs reports user assets and domains remain unaffected. The post ENS Npm Packages Compromised in Supply Chain Cyberattack Affecting 400 Libraries appeared first on Coinspeaker.

ENS Npm Packages Compromised in Supply Chain Cyberattack Affecting 400 Libraries

2025/11/25 04:41

Ethereum Name Service ENS $11.53 24h volatility: 3.2% Market cap: $436.61 M Vol. 24h: $62.46 M software packages were compromised in a supply chain cyberattack affecting over 400 code libraries on npm, a platform where developers share and download software tools. ENS Labs said user assets and domain names appear unaffected.

The team detected that packages starting with @ensdomains were affected around 5:49 a.m. UTC on Nov. 24 and has since updated package versions while changing security credentials, according to ENS Labs. ENS-operated websites including app.ens.domains showed no signs of impact.

The attack also compromised packages from Zapier, PostHog, Postman and AsyncAPI, according to Aikido Security, which first detected the campaign on Nov. 24.

Crypto Packages Among Victims

Several blockchain development libraries were caught in the broad attack. Affected packages include gate-evm-check-code2 and evm-checkcode-cli used for smart contract bytecode verification, create-hardhat3-app for Ethereum ETH $2 935 24h volatility: 5.4% Market cap: $355.26 B Vol. 24h: $32.16 B project scaffolding, and coinmarketcap-api for price data integration.

Other crypto libraries affected include ethereum-ens and crypto-addr-codec, which handles cryptocurrency address encoding. Over 40 packages within the @ensdomains scope were compromised.

The incident echoes a backdoor discovered in XRP Ledger packages in April, where malicious code was injected into xrpl.js to steal private keys.

How the Attack Works

Malicious packages were uploaded to npm between Nov. 21-23. The malware propagates by compromising maintainer accounts and injecting code into their packages. It executes automatically when developers run standard installation commands.

The malware collects developer passwords and access tokens from GitHub, npm and major cloud services. It publishes stolen data to public GitHub repositories and creates hidden access points on infected machines for future attacks.

A GitHub search shows 26,300 repositories now contain stolen credentials, spread across roughly 350 compromised accounts. The number continues to grow as the attack remains active.

Koi Security researchers discovered an additional threat. If the malware cannot steal credentials or send data out, it erases all files in the user’s home directory.

Developer Response

ENS Labs stated that developers who have not installed ENS packages within 11 hours of the 5:49 a.m. UTC detection are likely unaffected. Those who installed during that window should delete their node_modules folders, clear npm cache and change all credentials.

The incident follows a series of crypto security breaches that have tested infrastructure projects this year. GitHub is actively removing attacker-created repositories, though new ones continue to appear.

next

The post ENS Npm Packages Compromised in Supply Chain Cyberattack Affecting 400 Libraries appeared first on Coinspeaker.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Binance Visits Pakistan as Country Preps Major Crypto Policy Push

Binance Visits Pakistan as Country Preps Major Crypto Policy Push

The post Binance Visits Pakistan as Country Preps Major Crypto Policy Push appeared on BitcoinEthereumNews.com. Pakistan’s crypto market shows sharp activity over the last 30 days despite ongoing volatility, and the country now moves closer to a full regulatory structure. The shift gains speed after Binance executives arrived in Islamabad this week for direct talks with the country’s political and military leadership.  The meetings signal an important moment for Pakistan’s digital asset future as the government outlines strong support for regulation and oversight. High-Level Meetings Signal a National Crypto Strategy Binance CEO Richard Teng leads the exchange’s delegation during a series of meetings with the Prime Minister, the Chief of Defence Forces Field Marshal Asim Munir, and senior financial officials. The Prime Minister’s Office confirms a strong governmental commitment to building a transparent and secure framework for digital assets. The engagements show that Pakistan seeks structure, clarity, and global alignment as it transitions from an unregulated environment toward a regulated market. PVARA Chairman Bilal bin Saqib presides over the core discussions and outlines progress made by his newly formed authority. His briefing includes updates on licensing, market surveillance systems, and the country’s attempts to bring crypto service providers under a unified national standard. The government highlights the need to promote innovation while safeguarding users in one of the world’s fastest-growing digital markets. Regulatory Momentum Rises as Pakistan Eyes National Digital Currency Plans Pakistan wants a clear framework that supports financial innovation and ensures investor safety. The government views digital assets as a sector that can help modernize payment systems and expand financial inclusion. Saqib confirms that Pakistan studies stablecoin models and explores the creation of a state-backed digital currency as part of its broader modernization plan. Pakistan has already unveiled its first strategic Bitcoin reserve this year, which shows the government’s intent to participate in global digital finance. Saqib mentions that CBDC discussions continue as…
Share
BitcoinEthereumNews2025/12/08 01:15
BlackRock boosts AI and US equity exposure in $185 billion models

BlackRock boosts AI and US equity exposure in $185 billion models

The post BlackRock boosts AI and US equity exposure in $185 billion models appeared on BitcoinEthereumNews.com. BlackRock is steering $185 billion worth of model portfolios deeper into US stocks and artificial intelligence. The decision came this week as the asset manager adjusted its entire model suite, increasing its equity allocation and dumping exposure to international developed markets. The firm now sits 2% overweight on stocks, after money moved between several of its biggest exchange-traded funds. This wasn’t a slow shuffle. Billions flowed across multiple ETFs on Tuesday as BlackRock executed the realignment. The iShares S&P 100 ETF (OEF) alone brought in $3.4 billion, the largest single-day haul in its history. The iShares Core S&P 500 ETF (IVV) collected $2.3 billion, while the iShares US Equity Factor Rotation Active ETF (DYNF) added nearly $2 billion. The rebalancing triggered swift inflows and outflows that realigned investor exposure on the back of performance data and macroeconomic outlooks. BlackRock raises equities on strong US earnings The model updates come as BlackRock backs the rally in American stocks, fueled by strong earnings and optimism around rate cuts. In an investment letter obtained by Bloomberg, the firm said US companies have delivered 11% earnings growth since the third quarter of 2024. Meanwhile, earnings across other developed markets barely touched 2%. That gap helped push the decision to drop international holdings in favor of American ones. Michael Gates, lead portfolio manager for BlackRock’s Target Allocation ETF model portfolio suite, said the US market is the only one showing consistency in sales growth, profit delivery, and revisions in analyst forecasts. “The US equity market continues to stand alone in terms of earnings delivery, sales growth and sustainable trends in analyst estimates and revisions,” Michael wrote. He added that non-US developed markets lagged far behind, especially when it came to sales. This week’s changes reflect that position. The move was made ahead of the Federal…
Share
BitcoinEthereumNews2025/09/18 01:44