SlowMist CISO: NPM Supply Chain Attack Latest Variant "Shai-Hulud 3.0" is Coming, Please Be Vigilant
BlockBeats News, December 29, SlowMist Chief Security Officer 23pds issued a security alert, the latest variant of the NPM supply chain attack "Shai-Hulud 3.0" strikes again. All projects and platforms are advised to be on high alert. Previously, the suspected Trust Wallet API key leak may have led to the Shai-Hulud 2.0 attack.
Shai-Hulud is a series of self-propagating worm-like supply chain attacks targeting the NPM ecosystem, aiming to steal developer credentials, cloud keys, and environment secrets. The latest variant (referred to by the community as Shai-Hulud 3.0 or a new strain) was discovered by Aikido Security researcher Charlie Eriksen on December 28, 2025. Currently, its spread is limited and may be in a testing phase.
You may also like

Cybersecurity Firm Warns of Shai-Hulud 3.0 Threatening the NPM Ecosystem
Key Takeaways SlowMist’s CISO has issued a warning about Shai-Hulud 3.0, a significant threat targeting the NPM ecosystem…

SlowMist Warns of Return of Shai-Hulud 3.0 Supply Chain Attack
Key Takeaways SlowMist’s Chief Information Security Officer alerted the community about the resurgence of Shai-Hulud 3.0, an advanced…

Hackers Exploit Rainbow Six Siege Servers, Ubisoft Responds
Key Takeaways Hackers successfully breached Rainbow Six Siege, distributing enormous amounts of in-game currency. Players discovered unexpected changes…

Trust Wallet Investigates Browser Extension Security Incident
Key Takeaways A recent security incident in Trust Wallet’s browser extension has affected 2,596 wallets, leading to the…

Trust Wallet Users Experience $7 Million Loss Due to Hacked Chrome Extension
Key Takeaways Trust Wallet faced a significant security breach affecting its Chrome extension, resulting in over $7 million…

Cryptocurrency people who use candlestick charts for fortune telling
When fortune telling is depicted on candlestick charts and placed within the context of the cryptocurrency world, its explosive popularity stems not from the accuracy of its mystical claims, but from the fact that traders' collective anxiety about uncertainty has finally found an outlet.

Trust Wallet Browser Extension Security Incident Leads to Losses
Key Takeaways Trust Wallet identified a significant security breach in its browser extension version 2.68. Approximately over $6…

Trust Wallet Hack Results in $3.5 Million Loss for Major Wallet Holder
Key Takeaways A significant Trust Wallet hack led to the theft of $3.5 million from an inactive wallet.…

Social Engineering in the Crypto Universe: Safeguarding Your Assets in 2025
Key Takeaways Social engineering, a psychological manipulation tactic, has been the leading cause of crypto asset theft in…

Crypto Advice for Newcomers, Veterans, and Skeptics in 2026
Key Takeaways Newcomers should learn about the fundamentals of crypto and blockchain technology before investing. Experimenting with crypto…

Nofx’s Two-Month Journey from Stardom to Scandal: The Open Source Dilemma
Key Takeaways Nofx’s rise and fall in two months highlights inherent challenges in open source projects. A transition…

Key Market Information Discrepancy on December 19th, a Must-See! | Alpha Morning Report

Flare Token Appears to Face a Bearish Forecast with a Potential 23% Drop by December 22, 2025
Key Takeaways Flare (FLR) is projected to decrease by 23.40% from its current price, reaching $0.008989 by December…

Enhancing the Future of Cryptocurrency Exchange: Understanding the Landscape
Key Takeaways Cryptocurrency exchange platforms are pivotal for digital currency transactions, offering diverse services tailored to user needs.…

The Evolution of Cryptocurrency Exchanges and the Role of WEEX
Key Takeaways Cryptocurrency exchanges like WEEX play a crucial role in the digital asset trading ecosystem by providing…

The Deepfake Reckoning: Why Crypto’s Next Security Battle Will Be Against Synthetic Humans
Key Takeaways The rise of generative AI and deepfakes poses a significant threat to digital identity verification in…

Rejecting the "Security Theater": Wallet Security is Entering the Era of Verifiability

The Future of Cryptocurrency Exchange: A Look into WEEX and Beyond
Key Takeaways Cryptocurrency exchanges play a crucial role in the digital asset marketplace. WEEX focuses on offering secure…
Cybersecurity Firm Warns of Shai-Hulud 3.0 Threatening the NPM Ecosystem
Key Takeaways SlowMist’s CISO has issued a warning about Shai-Hulud 3.0, a significant threat targeting the NPM ecosystem…
SlowMist Warns of Return of Shai-Hulud 3.0 Supply Chain Attack
Key Takeaways SlowMist’s Chief Information Security Officer alerted the community about the resurgence of Shai-Hulud 3.0, an advanced…
Hackers Exploit Rainbow Six Siege Servers, Ubisoft Responds
Key Takeaways Hackers successfully breached Rainbow Six Siege, distributing enormous amounts of in-game currency. Players discovered unexpected changes…
Trust Wallet Investigates Browser Extension Security Incident
Key Takeaways A recent security incident in Trust Wallet’s browser extension has affected 2,596 wallets, leading to the…
Trust Wallet Users Experience $7 Million Loss Due to Hacked Chrome Extension
Key Takeaways Trust Wallet faced a significant security breach affecting its Chrome extension, resulting in over $7 million…
Cryptocurrency people who use candlestick charts for fortune telling
When fortune telling is depicted on candlestick charts and placed within the context of the cryptocurrency world, its explosive popularity stems not from the accuracy of its mystical claims, but from the fact that traders' collective anxiety about uncertainty has finally found an outlet.
Popular coins
Latest Crypto News
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Services:support@weex.com