Poland Becomes Sole EU MiCA Holdout After Parliament Fails to Overturn Veto
Crypto21:06
CZ Emphasizes Strict Private Key Isolation for Hardware Wallets
Macro21:06
US Small Business Bankruptcies Surge to Records as Inflation Persists
Crypto
SlowMist Detects New NPM Supply-Chain Poisoning Attack Linked to 'Shai-Hulud' Incident
11/27/2025, 10:36
11/27/2025, 11:06
AI SUMMARY
●SlowMist alerts on a new large-scale NPM supply-chain poisoning attack.
●The incident is linked to vectors used in the 'Shai-Hulud' attack from September 2025.
●Attackers are embedding malicious payloads directly into new software packages.
Blockchain security firm SlowMist has issued an alert regarding a new wave of large-scale package poisoning attacks targeting the NPM ecosystem. The malicious activity involves embedding dangerous payloads directly into software packages, posing a significant risk to developers and the broader supply chain.
SlowMist analysts note that this campaign is closely linked to the "Shai-Hulud" attack observed in September 2025. The similarities in attack vectors suggest a continuation or evolution of the same threat actor's tactics. Developers are strongly advised to exercise caution when managing dependencies and to verify the integrity of packages before installation.
[Update 1] Additional reports confirm that the new wave specifically embeds malicious payloads in fresh package waves, reinforcing the connection to the vectors used in the September 2025 incident.