Shai-Hulud Npm Supply Chain Attack is a threat campaign that compromised npm packages to reach users of crypto wallets.
Shai-Hulud Npm Supply Chain Attack is a threat campaign that compromised npm packages to reach users of crypto wallets. It relies on a supply-chain compromise in the npm ecosystem to deliver malicious payloads to wallet users, culminating in financial theft. The campaign's significance stems from its large financial impact on Trust Wallet users and its demonstration of how third-party dependencies can be weaponized against crypto platforms.
Trust Wallet reported that approximately $8.5 million in cryptocurrency was stolen from over 2,500 users due to a cyberattack linked to the Shai-Hulud npm supply chain attack. The attackers accessed Trust Wallet’s…