Over 400 npm code libraries, including Ethereum Name Service packages, were compromised in a supply chain cyberattack detected Nov. 24. ENS Labs reports user assets and domains remain unaffected. The post ENS Npm Packages Compromised in Supply Chain Cyberattack Affecting 400 Libraries appeared first on Coinspeaker.Over 400 npm code libraries, including Ethereum Name Service packages, were compromised in a supply chain cyberattack detected Nov. 24. ENS Labs reports user assets and domains remain unaffected. The post ENS Npm Packages Compromised in Supply Chain Cyberattack Affecting 400 Libraries appeared first on Coinspeaker.

ENS Npm Packages Compromised in Supply Chain Cyberattack Affecting 400 Libraries

2025/11/25 04:41

Ethereum Name Service ENS $11.53 24h volatility: 3.2% Market cap: $436.61 M Vol. 24h: $62.46 M software packages were compromised in a supply chain cyberattack affecting over 400 code libraries on npm, a platform where developers share and download software tools. ENS Labs said user assets and domain names appear unaffected.

The team detected that packages starting with @ensdomains were affected around 5:49 a.m. UTC on Nov. 24 and has since updated package versions while changing security credentials, according to ENS Labs. ENS-operated websites including app.ens.domains showed no signs of impact.

The attack also compromised packages from Zapier, PostHog, Postman and AsyncAPI, according to Aikido Security, which first detected the campaign on Nov. 24.

Crypto Packages Among Victims

Several blockchain development libraries were caught in the broad attack. Affected packages include gate-evm-check-code2 and evm-checkcode-cli used for smart contract bytecode verification, create-hardhat3-app for Ethereum ETH $2 935 24h volatility: 5.4% Market cap: $355.26 B Vol. 24h: $32.16 B project scaffolding, and coinmarketcap-api for price data integration.

Other crypto libraries affected include ethereum-ens and crypto-addr-codec, which handles cryptocurrency address encoding. Over 40 packages within the @ensdomains scope were compromised.

The incident echoes a backdoor discovered in XRP Ledger packages in April, where malicious code was injected into xrpl.js to steal private keys.

How the Attack Works

Malicious packages were uploaded to npm between Nov. 21-23. The malware propagates by compromising maintainer accounts and injecting code into their packages. It executes automatically when developers run standard installation commands.

The malware collects developer passwords and access tokens from GitHub, npm and major cloud services. It publishes stolen data to public GitHub repositories and creates hidden access points on infected machines for future attacks.

A GitHub search shows 26,300 repositories now contain stolen credentials, spread across roughly 350 compromised accounts. The number continues to grow as the attack remains active.

Koi Security researchers discovered an additional threat. If the malware cannot steal credentials or send data out, it erases all files in the user’s home directory.

Developer Response

ENS Labs stated that developers who have not installed ENS packages within 11 hours of the 5:49 a.m. UTC detection are likely unaffected. Those who installed during that window should delete their node_modules folders, clear npm cache and change all credentials.

The incident follows a series of crypto security breaches that have tested infrastructure projects this year. GitHub is actively removing attacker-created repositories, though new ones continue to appear.

next

The post ENS Npm Packages Compromised in Supply Chain Cyberattack Affecting 400 Libraries appeared first on Coinspeaker.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Team Launches AI Tools to Boost KYC and Mainnet Migration for Investors

Team Launches AI Tools to Boost KYC and Mainnet Migration for Investors

The post Team Launches AI Tools to Boost KYC and Mainnet Migration for Investors appeared on BitcoinEthereumNews.com. The Pi Network team has announced the implementation of upgrades to simplify verification and increase the pace of its Mainnet migration. This comes before the token unlock happening this December. Pi Network Integrates AI Tools to Boost KYC Process In a recent blog post, the Pi team said it has improved its KYC process with the same AI technology as Fast Track KYC. This will cut the number of applications waiting for human review by 50%. As a result, more Pioneers will be able to reach Mainnet eligibility sooner. Fast Track KYC was first introduced in September to help new and non-users set up a Mainnet wallet. This was in an effort to reduce the long wait times caused by the previous rule. The old rule required completing 30 mining sessions before qualifying for verification. Fast Track cannot enable migration on its own. However, it is now fully part of the Standard KYC process which allows access to Mainnet. This comes at a time when the network is set for another unlock in December. About 190 million tokens will unlock worth approximately $43 million at current estimates.  These updates will help more Pioneers finish their migration faster especially when there are fewer validators available. This integration allows Pi’s validation resources to serve as a platform utility. In the future, applications that need identity verification or human-verified participation can use this system. Team Releases Validator Rewards Update The Pi Network team provided an update about validator rewards. They expect to distribute the first rewards by the end of Q1 2026. This delay happened because they needed to analyze a large amount of data collected since 2021. Currently, 17.5 million users have completed the KYC process, and 15.7 million users have moved to the Mainnet. However, there are around 3 million users…
Share
BitcoinEthereumNews2025/12/06 16:08
Solana Nears $124 Support Amid Cautious Sentiment and Liquidity Reset Potential

Solana Nears $124 Support Amid Cautious Sentiment and Liquidity Reset Potential

The post Solana Nears $124 Support Amid Cautious Sentiment and Liquidity Reset Potential appeared on BitcoinEthereumNews.com. Solana ($SOL) is approaching a critical support level at $124, where buyers must defend to prevent further declines amid cautious market conditions. A successful hold could initiate recovery toward $138 or higher, while failure might lead to deeper corrections. Solana’s price risks dropping to $124 if current support zones weaken under selling pressure. Reclaiming key resistance around $138 may drive $SOL toward $172–$180 targets. Recent data shows liquidity resets often precede multi-week uptrends, with historical patterns suggesting potential recovery by early 2026. Solana ($SOL) support at $124 tested amid market caution: Will buyers defend or trigger deeper drops? Explore analysis, liquidity signals, and recovery paths for informed trading decisions. What Is the Current Support Level for Solana ($SOL)? Solana ($SOL) is currently testing a vital support level at $124, following a decline from the $144–$146 resistance zone. Analysts from TradingView indicate that after failing to maintain momentum above $138, the token dipped toward $131 and mid-range support near $134. This positioning underscores the importance of buyer intervention to stabilize the price and prevent further erosion. Solana ($SOL) is in a crucial stage right now, with possible price drops toward important support zones. Recent price activity signals increased downside risks, analysts caution. TradingView contributor Ali notes that Solana may find quick support at $124 after falling from the $144–$146 resistance range. The token eventually tested $131 after failing to hold over $138 and plummeting toward mid-range support near $134. Source: Ali Market indicators reveal downward momentum, with potential short-term volatility around $130–$132 before possibly easing to $126–$127. Should this threshold break, $SOL could slide to the firmer support at $124–$125, according to observations from established charting platforms. Overall sentiment remains guarded, as highlighted by experts monitoring on-chain data. Ali warns that without robust buying interest, additional selling could intensify. TradingView analyst…
Share
BitcoinEthereumNews2025/12/06 16:33