Open Source 2025-11-23 · 1 day ·Credential Theft, Self Propagation

ENS npm packages hit by Shai-Hulud

Part of the Sha1-Hulud worm spread across npm packages campaign

The Sha1-Hulud "Second Coming" npm worm compromised many Ethereum Name Service packages, including @ensdomains/ensjs, @ensdomains/ens-contracts, @ensdomains/ens-validation, ethereum-ens, and supporting ENS libraries.

Story

ENS was one of the largest package groups in the Sha1-Hulud "Second Coming" npm wave. The compromised scope included core ENS packages, support libraries, CCIP-read components, DNSSEC tooling, and the legacy ethereum-ens package.

The attack used the same basic shape as the broader Shai-Hulud family: compromised npm publishing access, malicious package releases, credential theft, and self-propagation through stolen tokens. ENS is modeled separately because the affected package set is large enough to matter on its own.

The impact was developer-side, not a direct compromise of ENS smart contracts. Affected packages could run during installation or use in build environments, putting npm tokens, GitHub tokens, and other developer credentials at risk.

This record keeps the package list explicit so downstream analysis can answer which ENS artifacts were affected. The campaign record holds the cross-package story; this attack records the ENS trust boundary and artifact scope.

Affected Artifacts

Incident Context

Motive
Credential Theft
Attribution
Group
Cause
Compromised Account Credentials
Transitive
No
Actor
Third Party

External References

Source record: oss/attacks/ensdomains-npm/meta.yaml