Friday, January 30, 2026
cryptonews100
No Result
View All Result
CryptoNews100
No Result
View All Result
Home Alt Coins Solana

Trust Wallet links $8.5 million crypto theft to Shai-Hulud NPM attack

cryptonews100_tggfrn by cryptonews100_tggfrn
January 3, 2026
in Solana
0
Trust Wallet links $8.5 million crypto theft to Shai-Hulud NPM attack
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
Sign up an get up to $1000 USDT!


Trust Wallet

Trust Wallet believes the compromise of its net browser to steal roughly $8.5 million from over 2,500 crypto wallets is probably going associated to an “industry-wide” Sha1-Hulud attack in November.

Related articles

Hold off on Nasdaq’s tokenized securities plan — TradingView News

SOL price drops further as Solana validators fall 68% — TradingView News

January 30, 2026
Solana has tanked since spot solana ETFs launched, despite the funds only recording positive flows to date

Solana has tanked since spot solana ETFs launched, despite the funds only recording positive flows to date

January 29, 2026

Trust Wallet, a crypto pockets utilized by over 200 million individuals, allows customers to retailer, ship, and obtain Bitcoin, Ethereum, Solana, and 1000’s of different cryptocurrencies and digital tokens through an online browser extension and free cellular apps.

As BleepingComputer previously reported, this December twenty fourth incident resulted within the theft of thousands and thousands of {dollars} in cryptocurrency from the compromised wallets of Trust Wallet customers.

Wiz

This occurred after attackers added a malicious JavaScript file to model 2.68.0 of Trust Wallet’s Chrome extension, which stole delicate pockets information and enabled risk actors to execute unauthorized transactions.

“Our Developer GitHub secrets and techniques have been uncovered within the attack, which gave the attacker entry to our browser extension supply code and the Chrome Internet Retailer (CWS) API key,” the corporate said in a Tuesday replace.

“The attacker obtained full CWS API entry through the leaked key, permitting builds to be uploaded instantly with out Trust Wallet’s normal launch course of, which requires inner approval/handbook evaluate.”

Trust Wallet attack

As Trust Wallet defined, within the subsequent stage of the attack, the risk actor registered the area metrics-trustwallet.com and the subdomain api.metrics-trustwallet.com to host malicious code, which was later referenced in a trojanized model of the Trust Wallet extension.

The modified model of the official extension was constructed utilizing supply code obtained through uncovered GitHub developer secrets and techniques, permitting the attacker to embed malicious code that collected delicate pockets information with out conventional code injection.

Utilizing a leaked CWS key, the attacker revealed model 2.68 to the Chrome Internet Retailer, which was mechanically launched after passing evaluate, bypassing Trust Wallet’s inner approval processes.

In response to the incident, Trust Wallet revoked all launch APIs to block makes an attempt to launch new variations and ensured that the hackers could not steal further pockets information by reporting the malicious domains to the NiceNIC registrar, which promptly suspended them.

Trust Wallet has additionally started reimbursing affected users and warned them that risk actors are at the moment impersonating Trust Wallet assist accounts, pushing faux compensation varieties, and working scams through Telegram adverts.

The Shai-Hulud malware marketing campaign

Sha1-Hulud (often known as Shai-Hulud 2.0) was a provide chain attack focusing on the npm software program registry, which lists over 2 million packages.

Through the initial Shai-Hulud outbreak in early September, risk actors compromised over 180 npm packages utilizing a self-propagating payload and used it to steal developer secrets and techniques and API keys with the TruffleHog software.

Shai-Hulud 2.0 grew exponentially and impacted over 800 packages after including over 27,000 malicious packages to the npm repository that used malicious code to gather developer and CI/CD secrets and techniques and publish them on GitHub.

In complete, Sha1-Hulud exposed around 400,000 raw secrets and revealed stolen information throughout over 30,000 GitHub repositories, with over 60% of the leaked NPM tokens nonetheless legitimate as of December 1st.

“Attackers are perfecting credential harvesting operations utilizing the npm ecosystem and GitHub,” Wiz safety researchers warned final month.

“Given the attackers’ rising sophistication and success to date, we predict continued assaults, each utilizing comparable TTPs and leveraging the credential trove harvested to date.”


Wiz

Whether or not you are cleansing up previous keys or setting guardrails for AI-generated code, this information helps your group construct securely from the beginning.

Get the cheat sheet and take the guesswork out of secrets and techniques administration.



Source link

Tags: attackcryptoLinksmillionnpmShaiHuludtheftTrustwallet
Share76Tweet47
Drive and walk to earn crypto!

Related Posts

Hold off on Nasdaq’s tokenized securities plan — TradingView News

SOL price drops further as Solana validators fall 68% — TradingView News

by cryptonews100_tggfrn
January 30, 2026
0

Solana (SOL) is below strain as its price continues to say no.The cryptocurrency is at present buying and selling at...

Solana has tanked since spot solana ETFs launched, despite the funds only recording positive flows to date

Solana has tanked since spot solana ETFs launched, despite the funds only recording positive flows to date

by cryptonews100_tggfrn
January 29, 2026
0

Solana spot ETFs have but to document weekly outflows since their itemizing, but the worth of the token has been...

Thinking About Investing in Crypto in 2026? Here Are My Top Picks

Thinking About Investing in Crypto in 2026? Here Are My Top Picks

by cryptonews100_tggfrn
January 29, 2026
0

These 3 cryptocurrencies ought to outperform the market in 2026.In the course of the previous 90 days, solely a dozen...

Bybit Leads Global XAUT Spot Trading with ~16% Market Share as Tokenized Gold Rallies to New Highs

Bybit Leads Global XAUT Spot Trading with ~16% Market Share as Tokenized Gold Rallies to New Highs

by cryptonews100_tggfrn
January 29, 2026
0

DUBAI, UAE, Jan. 28, 2026 /CNW/ -- Bybit, the world's second-largest cryptocurrency trade by buying and selling quantity, introduced that...

Could Buying Hyperliquid (HYPE) Today Set You Up for Life?

Could Buying Hyperliquid (HYPE) Today Set You Up for Life?

by cryptonews100_tggfrn
January 29, 2026
0

Hyperliquid soared as crypto traders flocked to make use of leverage, however a number of waves of liquidations have damped...

Load More

Crypto Fear & Greed Index

Latest Crypto Fear & Greed Index

Recent News

Sui Wallet Unveils Revolutionary DeepBook Point Program Integration for Enhanced User Rewards

January 30, 2026
Would you trust the Trump family with all your money?

Would you trust the Trump family with all your money?

January 30, 2026

스테이넥스, RWA와 디파이 결합해 여행 혁신

January 30, 2026

Categories

  • Bitcoin
  • Cardano
  • Chainlink
  • Cryptocurrency
  • Dogecoin
  • Ethereum
  • Exchanges
  • Pokadot
  • Polygon
  • Real World Assets
  • Shiba Inu
  • Solana
  • sui
  • World Liberty Financial
  • XRP

Download the official CryptoNews100 Android App! Click the button below:

Tags

ADA (280) Bitcoin (1340) BTC (340) Buy (413) Cardano (567) ChainLink (411) crypto (1699) Cryptocurrency (538) DOGE (231) Dogecoin (568) DOT (196) ETF (346) ETFs (185) ETH (316) Ethereum (786) eyes (187) Financial (177) Heres (176) Inu (392) investors (177) Launch (177) launches (185) Link (181) market (550) million (202) News (699) Polkadot (295) POLYGON (241) prediction (397) Presale (287) price (1220) rally (260) RWA (262) SHIB (200) Shiba (404) Solana (663) Stablecoin (181) Sui (403) today (186) token (191) top (357) TradingView (268) Trump (224) world (187) XRP (949)

© 2023 Crypto News100 All Rights Reserved.
By visiting this website, you understand that the content provided within is for educational and entertainment purposes only. Nothing on this site may be constituted as financial advice and this site is not directing you to make any investments in cryptocurrency or in anything else. Thank you for visiting and please proceed responsibly.
As an Amazon Associate I earn from qualifying purchases.

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Alt Coins
    • Cardano
    • Dogecoin
    • Litecoin
    • Pokadot
    • Polygon
    • Shiba Inu
    • Solana
    • XRP
  • Crypto Related DEALS

© 2023 Crypto News100 All Rights Reserved.
By visiting this website, you understand that the content provided within is for educational and entertainment purposes only. Nothing on this site may be constituted as financial advice and this site is not directing you to make any investments in cryptocurrency or in anything else. Thank you for visiting and please proceed responsibly.
As an Amazon Associate I earn from qualifying purchases.