PANews reported on December 29th that 23pds, Chief Information Security Officer of SlowMist Technology, issued a security alert: a new variant of the NPM supplyPANews reported on December 29th that 23pds, Chief Information Security Officer of SlowMist Technology, issued a security alert: a new variant of the NPM supply

SlowMist: Project teams should be wary of the latest variant of NPM supply chain attacks, Shai-Hulud 3.0.

2025/12/29 13:10

PANews reported on December 29th that 23pds, Chief Information Security Officer of SlowMist Technology, issued a security alert: a new variant of the NPM supply chain attack, "Shai-Hulud 3.0," has resurfaced. Projects and platforms are urged to take precautions. Previously, it was suspected that the Trust Wallet API key leak was caused by the Shai-Hulud 2.0 attack. Shai-Hulud is a series of self-propagating worm-like supply chain attacks targeting the NPM ecosystem, used to steal developer credentials, cloud keys, and environment secrets. The latest variant (referred to by the community as Shai-Hulud 3.0 or the new strain) was discovered on December 28, 2025, by Charlie Eriksen, a researcher at Aikido Security. Currently, its spread is limited and may only be in the testing phase.

Market Opportunity
Overtake Logo
Overtake Price(TAKE)
$0.42304
$0.42304$0.42304
+30.49%
USD
Overtake (TAKE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.