Hackers exploit Ethereum contracts to hide malware in npm packages
- Malware uses Ethereum contracts for hidden commands
- Malicious npm packages exploit open source libraries
- Fake campaign includes cryptocurrency trading bots
Um report A recent report from security firm ReversingLabs revealed that hackers are using Ethereum smart contracts as part of a new technique to hide malware in npm packages. This approach was identified in two packages published in July, called "colortoolsv2" and "mimelib2," which extracted command and control instructions directly from on-chain contracts.
According to researcher Lucija Valentic, the packets executed obfuscated scripts that queried Ethereum contracts to locate the payload for the next stage of the infection. This method replaces the traditional practice of inserting links directly into the code, making it more difficult for library maintainers to detect and remove the malware. "This is something we've never seen before," Valentic said, highlighting the sophistication of the technique and the speed with which threat actors adapt their strategies.
In addition to using smart contracts, the attackers created fake GitHub repositories with cryptocurrency themes, such as trading bots, that displayed artificially inflated activity. Fake stars, automated commits, and fictitious maintainer profiles were used to trick developers into trusting the packages and including them in their projects.
Although the identified packages have already been removed after a report, ReversingLabs warned that the incident is part of a larger campaign aimed at compromising the npm and GitHub ecosystems. Among the fake repositories was "solana-trading-bot-v2," which featured thousands of shallow commits to gain credibility while inserting malicious dependencies.
Valentic explained that the investigation revealed evidence of a broader, coordinated effort aimed at infiltrating malicious code into libraries widely used by developers. "These recent attacks by threat actors, including the creation of sophisticated attacks using blockchain and GitHub, show that repository attacks are evolving," he emphasized.
The company had also identified previous campaigns that abused developers' trust in open-source packages. This latest campaign, however, demonstrates how blockchain technology is being creatively incorporated into malware schemes, increasing the complexity of security in the cryptocurrency-related application and project development ecosystem.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Goldman and T. Rowe sign $1 billion partnership as Wall Street targets retirement cash
Share link:In this post: Goldman Sachs is buying a $1 billion, 3.5% stake in T. Rowe Price to push private assets into retirement accounts. The partnership will launch target-date funds, co-branded portfolios, and advice services by mid-2025. Citigroup also announced a deal giving BlackRock $80 billion in client assets to manage starting in Q4.

Fed chair contender Hassett slams central bank for mission creep and fading independence
Share link:In this post: Kevin Hassett accused the Fed of losing independence and overstepping its mandate. He slammed the job data system as broken and called for urgent modernization. Kevin backed a full review of the Fed’s roles in policy, regulation, and research.

Bitmain is hit with a lawsuit alleging breach of hosting agreement
Share link:In this post: Old Const says Bitmain faked breaches to end their deal and seize mining equipment. The company wants a court order stating that disputes must stay in Texas based on the agreement. Old Const is seeking an injunction, damages, and legal fees from Bitmain.

El Salvador joins the gold rush and acquires 13,999 troy ounces
Share link:In this post: El Salvador’s central bank bought 13,999 troy ounces of gold worth $50 million. The bank says gold will diversify reserves and provide stability, especially as Bitcoin holdings remain volatile. The move follows the global trend of central banks buying over 1,000 tonnes of gold collectively.

Trending news
MoreCrypto prices
More








