npm Tightens Token Permissions in Response to Attacks, Web3 Security Experts Question Adequacy of Measures
npm has begun tightening high-privilege access tokens in response to the recent "Mini Shai-Hulud" supply chain attack impacting Web3 developers. The platform has revoked granular access tokens with write permissions and requires users to immediately rotate their keys and shift to the Trusted Publishing release mechanism.
Platform Action Initiated
The immediate goal of this adjustment is to curb the latest wave of this malware’s spread. Attackers previously exploited writable tokens to bypass two-factor authentication, publishing malicious packages or contaminating existing package versions in the npm registry.
However, several security researchers believe npm's actions are somewhat belated and mainly limit further propagation, without addressing malicious code that has already infiltrated developers' devices.
Infected Environments May Continue to Leak Information
Researchers point out that revoking tokens may indeed reduce the number of new malicious versions being published, but offers limited help for already compromised development environments. The worm embeds itself within IDE and AI assistant configurations, repeatedly triggering whenever developers use related tools.
This means that even if developers delete project files or clean node_modules, malicious scripts may still reinfect the environment during subsequent operations and continue to steal sensitive information.
Attack Targets Include Cloud Credentials and Wallet Mnemonics
Publicly available descriptions show that such malicious programs not only steal standard development credentials but also collect AWS cloud service credentials, crypto wallet mnemonics, and other high-value data. The related information is then exfiltrated via the GitHub official API, making the traffic resemble normal development activity and increasing the difficulty of detection.
- Attackers took control of a legitimate npm account, atool
- 637 malicious versions were published within 27 minutes
- Involved 323 packages, with approximately 16 million weekly downloads
Security Community Criticizes Reactive Response
MetaMask Chief Security Researcher Taylor Monahan and others have criticized the platform's current approach, arguing it is more about assessing the scale of the issue rather than eradicating the infection itself. Another researcher also pointed out that merely restricting access rights cannot replace thorough analysis and removal of malicious program behaviors.
For Web3 teams, this incident once again highlights that the development toolchain has become a high-risk entry point. Especially with AI coding assistants now deeply integrated into daily workflows, once the configuration layer is compromised by malicious scripts, the impact may exceed the boundaries of a single project.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Crypto: In 2026, BNB Chain Emerges as the Global Leader in RWA Growth

BlackRock Bitcoin ETF outflows hit $19.23M as sector sheds $463M in four days
Pi Network Price Prediction: Can PI Hold Its Wedge Breakout Before the Upgrade?

As AI controversies escalate, hedge funds buy tech stocks at the fastest pace in 15 months
Hedge funds have recorded net purchases of US TMT stocks on 10 out of the past 11 trading days, rebuilding tech long positions at the fastest pace in 15 months. However, an AI policy storm has struck at the "worst possible time"—calls by AI giants to slow down development have been rejected, and regulatory uncertainty has directly hit Asian tech stocks such as Softbank. As the tech sector's bullish run coincides with Super Central Bank Week, the sector now faces a severe test.
