A massive supply chain breach has compromised over 400 NPM packages in what security researchers are calling a worm-style propagation attack. The incident specifically targeted critical infrastructure, affecting major ENS libraries and several widely-used crypto development tools. Attackers managed to exfiltrate developer authentication credentials along with private wallet keys, potentially exposing both project codebases and user funds. The attack vector appears to leverage dependency chains, allowing malicious code to spread automatically across connected packages. Development teams relying on affected libraries are urged to rotate credentials immediately and conduct thorough security audits of their deployment environments.

ENS0,62%
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 8
  • Repost
  • Share
Comment
Add a comment
Add a comment
LiquidationWizardvip
· 2025-11-27 15:02
More than 400 packages have been compromised, this time it's really harsh...

---

No wonder so many projects have gone wrong recently, it turns out the entire Supply Chain has been infiltrated

---

Wallet Private Key has been exposed? Oh my god, who would dare to use it now?

---

dependency is indeed a ticking time bomb, one bad package can cause a chain reaction

---

Now I have to change passwords and audit, the development team is probably going to collapse these days

---

This worm-like propagation is really hard to defend against, the security of npm's ecosystem definitely needs reflection.
View OriginalReply0
LootboxPhobiavip
· 2025-11-25 23:48
Here we go again? How many times has the npm ecosystem crashed? It's really frustrating, 400 packages have directly fallen apart, who will be able to walk out alive this time...
View OriginalReply0
WalletWhisperervip
· 2025-11-24 17:08
Over 400 npm packages hacked? This is pretty brutal, directly stealing wallet keys... Developers better hurry up and change their passwords.
View OriginalReply0
GasGuzzlervip
· 2025-11-24 17:07
Damn, have all 400 packages collapsed? This supply chain issue is really something, the wallet private keys have all been exposed, we need to quickly change the credentials.
View OriginalReply0
BearMarketLightningvip
· 2025-11-24 16:58
Over 400 packages have been messed up, and now the dependency hell has completely fallen.
View OriginalReply0
MEVSandwichvip
· 2025-11-24 16:53
Over 400 packages have been compromised? This is pretty serious, better change the keys quickly.
View OriginalReply0
RektCoastervip
· 2025-11-24 16:53
What the hell, it's coming again? The npm ecosystem is really outrageous, 400 packages were breached together, let's be smarter this time everyone.
View OriginalReply0
CryptoGoldminevip
· 2025-11-24 16:46
400 packages were attacked, and the ROI recovery period will have to be extended by several months.
View OriginalReply0
  • Pin