Slow Fog: All project parties need to be vigilant about the latest variant of NPM supply chain attacks, Shai-Hulud 3

Dec 29, 2025 13:11:53

Share to

The Chief Information Security Officer of Slow Fog Technology, 23pds, has issued a security alert regarding the latest variant of the NPM supply chain attack, "Shai-Hulud 3." All project teams and platforms are advised to take precautions. It was previously suspected that the leak of the Trust Wallet API key could have led to the Shai-Hulud 2 attack.

Shai-Hulud is a series of self-propagating worm-like supply chain attacks targeting the NPM ecosystem, aimed at stealing developer credentials, cloud keys, and environment secrets. The latest variant (referred to by the community as Shai-Hulud 3 or new strain) was discovered on December 28, 2025, by Aikido Security researcher Charlie Eriksen. The current spread is limited and may only be in the testing phase.

Recent Fundraising

More
$10M 12月 30, 2025
-- 12月 26, 2025
$1M 12月 25, 2025

New Tokens

More
12月 30, 2025
oooo OOOO
12月 30, 2025
12月 29, 2025

Latest Updates on 𝕏

More
1月 02
1月 02