Trust Wallet hit by network compromise
Incident
Summary
Hide ▲
Show ▼
Trust Wallet said its Chrome extension was likely compromised through the second iteration of Shai-Hulud in November 2025, exposing GitHub secrets and a Chrome Web Store API key that let attackers upload a trojanized build. The malicious version 2.68.0 update on December 24, 2025 added a malicious JavaScript file and backdoor behavior that harvested wallet mnemonic phrases, leading to the theft of about $8.5 million from 2,520 wallet addresses. Trust Wallet said it has revoked its release APIs, is reviewing reimbursement claims for affected users, and has reported the attacker infrastructure, including metrics-trustwallet.com and api.metrics-trustwallet.com.
Related Happenings
Shai-Hulud worm clone activity on NPM
Malware Activity
H score69
First: 18.05.2026 12:45
Last: 18.05.2026 12:45
Sources 1
About this happening:
The Shai-Hulud malware activity has continued to evolve across the npm supply chain and related developer ecosystems. It first infected npm packages in September 202...
Shai-Hulud worm clone activity on NPM
Malware ActivityAbout this happening: The Shai-Hulud malware activity has continued to evolve across the npm supply chain and related developer ecosystems. It first infected npm packages in September 202...
Shai-Hulud supply-chain campaign spreading via stolen CI/CD credentials
Campaign
H score56
First: 12.05.2026 14:29
Last: 12.05.2026 14:29
Sources 1
About this happening:
GitHub said it removed more than 500 compromised npm packages in September 2025 and moved to harden publishing after early Shai-Hulud activity. In May 2026, researcher...
Shai-Hulud supply-chain campaign spreading via stolen CI/CD credentials
CampaignAbout this happening: GitHub said it removed more than 500 compromised npm packages in September 2025 and moved to harden publishing after early Shai-Hulud activity. In May 2026, researcher...
Elementary-data package hit by network compromise
Incident
H score36
First: 27.04.2026 18:17
Last: 27.04.2026 18:17
Sources 1
About this happening:
The elementary-data project suffered a malicious release compromise that exposed users of PyPI and GitHub Container Registry to a backdoored package and image. An...
Elementary-data package hit by network compromise
IncidentAbout this happening: The elementary-data project suffered a malicious release compromise that exposed users of PyPI and GitHub Container Registry to a backdoored package and image. An...
FakeWallet Apple App Store wallet-stealing apps
Malware Activity
H score8
First: 21.04.2026 00:52
Last: 21.04.2026 00:52
Sources 1
About this happening:
The FakeWallet app set turned the Apple App Store into a delivery channel for 26 malicious wallet lookalikes, putting crypto holders at risk of account takeover and th...
FakeWallet Apple App Store wallet-stealing apps
Malware ActivityAbout this happening: The FakeWallet app set turned the Apple App Store into a delivery channel for 26 malicious wallet lookalikes, putting crypto holders at risk of account takeover and th...
EngageLab SDK intent redirection security flaw
Vulnerability
H score29
First: 09.04.2026 20:26
Last: 09.04.2026 20:26
Sources 1
About this happening:
A now-patched intent redirection vulnerability in the EngageLab SDK could let malicious apps bypass the Android security sandbox and access private data in apps us...
EngageLab SDK intent redirection security flaw
VulnerabilityAbout this happening: A now-patched intent redirection vulnerability in the EngageLab SDK could let malicious apps bypass the Android security sandbox and access private data in apps us...
Timeline
-
02.01.2026 16:19 1 articles · 6mo ago
Trust Wallet Chrome extension compromise on December 24
Technical Analysis UpdateAttackers added a malicious JavaScript file to version 2.68.0 of Trust Wallet's Chrome extension, stole sensitive wallet data, and enabled unauthorized transactions; the same compromise exposed Developer GitHub secrets and the Chrome Web Store (CWS) API key, and a trojanized build was published after malicious code was hosted on metrics-trustwallet.com and api.metrics-trustwallet.com.
Show sources
- Trust Wallet links $8.5 million crypto theft to Shai-Hulud NPM attack — www.bleepingcomputer.com — 02.01.2026 16:19
-
02.01.2026 16:19 3 articles · 6mo ago
Trust Wallet links compromise to Sha1-Hulud and revokes release APIs
Mitigation Patch UpdateTrust Wallet said the compromise was likely related to an industry-wide Sha1-Hulud attack in November, disclosed that Developer GitHub secrets exposed the browser extension source code and the CWS API key, revoked all release APIs, reported the malicious domains to NiceNIC for suspension, started reimbursing affected users, and warned about impersonation scams using fake compensation forms and Telegram ads.
Show sources
- Trust Wallet links $8.5 million crypto theft to Shai-Hulud NPM attack — www.bleepingcomputer.com — 02.01.2026 16:19
- Trust Wallet links $8.5 million crypto theft to Shai-Hulud NPM attack — www.bleepingcomputer.com — 02.01.2026 16:19
- Trust Wallet Chrome Extension Hack Drains $8.5M via Shai-Hulud Supply Chain Attack — thehackernews.com — 31.12.2025 18:29