According to BlockBeats, a security alert has been issued by SlowMist Technology's Chief Information Security Officer, 23pds, regarding a new variant of the NPM supply chain attack known as 'Shai-Hulud 3.0.' Project teams and platforms are advised to take preventive measures. Previously, it was suspected that the Trust Wallet API key leak might have been caused by the Shai-Hulud 2.0 attack.
Shai-Hulud is a series of self-propagating worm-like supply chain attacks targeting the NPM ecosystem, aimed at stealing developer credentials, cloud keys, and environment secrets. The latest variant, referred to by the community as Shai-Hulud 3.0 or the new strain, was discovered on December 28, 2025, by Aikido Security researcher Charlie Eriksen. Currently, its spread is limited, suggesting it may still be in the testing phase.