# Пов'язані статті щодо Worm

Центр новин HTX надає останні статті та поглиблений аналіз на тему "Worm", що охоплює ринкові тренди, оновлення проєктів, технологічні розробки та регуляторну політику в криптоіндустрії.

Hackers Breached a Popular Library for JS Developers: Why the npm Vulnerability is Dangerous for Crypto

Hackers have compromised the popular JavaScript utility 'keyv' through a developer account, triggering a major supply-chain attack. Starting August 4, 2026, they injected malicious code into new versions. The code auto-executes during the routine `npm install` command, stealthily downloading malware onto developers' machines. The malware hunts for highly sensitive data: npm and GitHub credentials, AWS cloud keys, SSH access, KeePass files, IDE configurations, and—critically—cryptocurrency wallet files, seed phrases, and private keys for networks like Solana and Monero. Stolen data is encrypted and exfiltrated via public GitHub repositories and servers contacted through an Ethereum smart contract. The worm self-propagates by using stolen credentials to publish infected updates to other popular npm packages, deepening its persistence. Current estimates indicate between 444 and 868 packages (over 1,300 versions) are affected. This incident is particularly dangerous for the crypto industry. A breach on a developer's machine can grant attackers access to project code, servers, and ultimately lead to major fund thefts. Analysis suggests this is the third wave of the 'Shai-Hulud' campaign, highlighting systemic trust issues within the npm ecosystem rather than a one-off event. It underscores that even routine actions can pose severe risks, urging crypto teams to exercise extreme caution with their tooling.

cryptonews.ru08/06 15:51

Hackers Breached a Popular Library for JS Developers: Why the npm Vulnerability is Dangerous for Crypto

cryptonews.ru08/06 15:51

活动图片