SlowMist Warns of New Shai-Hulud 3.0 NPM Supply Chain Attack Variant

iconKuCoinFlash
Share
Share IconShare IconShare IconShare IconShare IconShare IconCopy
AI summary iconSummary

expand icon
On-chain news emerged on December 29 as SlowMist’s CISO 23pds warned of a new NPM supply chain attack variant called Shai-Hulud 3.0. The malware automatically spreads to steal developer credentials and cloud keys. Aikido Security’s Charlie Eriksen found the strain on December 28, 2025. The attack remains limited, likely in a test phase. New token listings should monitor for potential exposure.

In accordance with PANews, SlowMist Chief Information Security Officer 23pds issued a security alert on December 29 about the latest variant of the NPM supply chain attack, dubbed 'Shai-Hulud 3.0.' The attack, which spreads automatically, is designed to steal developer credentials, cloud keys, and environment secrets. Aikido Security researcher Charlie Eriksen discovered the new strain on December 28, 2025, and it is currently limited in scope, likely in a testing phase.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.