Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Kraken sues crypto derivatives firm PowerTrade over missing funds

June 25, 2026

Dunamu leads seven-firm race for South Korea’s seized crypto custody contract

June 25, 2026

ICE And OKX Tokenized Equities Venture Shows Wall Street Moving On-Chain

June 25, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Malicious npm Packages Exploit Ethereum Smart Contracts
Malicious npm Packages Exploit Ethereum Smart Contracts
Security and Privacy

Malicious npm Packages Exploit Ethereum Smart Contracts

September 3, 2025No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A malicious campaign targeting developers through npm and GitHub repositories has been uncovered, featuring an unusual method of using Ethereum smart contracts to conceal command-and-control (C2) infrastructure.

The campaign first came to light in early July when ReversingLabs researcher Karlo Zanki discovered a package named “colortoolsv2” on npm.

The package was quickly removed, but attackers attempted to continue the operation by publishing a duplicate package, “mimelib2.” Both packages deployed a second-stage malware payload through blockchain infrastructure.

What’s New in This Campaign

While malicious npm downloaders appear regularly, these typically contain URLs or scripts embedded in the package itself.

In contrast, colortoolsv2 and mimelib2 leveraged Ethereum smart contracts to store and deliver the URLs used for fetching the second-stage malware. This tactic made detection significantly harder, as the malicious infrastructure was hidden within the blockchain code rather than inside the package files.

“Downloaders are […] published weekly, [but] this use of smart contracts to load malicious commands is something we haven’t seen previously,” RL researchers said.

“It highlights the fast evolution of detection evasion strategies by malicious actors who are trolling open source repositories and developers.”

Read more on smart contract abuse in cybersecurity: Supply Chain Attack Uses Smart Contracts for C2 Ops

GitHub Repositories Disguised as Trading Tools

ReversingLabs investigators also found that the npm packages were tied to a broader campaign across GitHub. Fake repositories, presented as cryptocurrency trading bots, appeared well-established with thousands of commits, multiple maintainers and active watchers.

However, much of this activity was fabricated. According to ReversingLabs, stars and watchers came from accounts created in July, each with minimal activity. Additionally, Puppet accounts acted as maintainers to inflate legitimacy, and forks and commits were used to create the illusion of popularity.

See also  Canadian teens allegedly stole over $4M in crypto by impersonating Coinbase support

The most prominent example was a repository named “solana-trading-bot-v2,” which bundled the malicious npm package. Although it appeared to be a serious project, closer inspection revealed the network of fake accounts supporting it.

Growing Threats to Open Source

The discovery adds to a growing list of software supply chain attacks targeting crypto-focused developers. 

According to ReversingLabs’s 2025 Software Supply Chain Security report, there were 23 such campaigns in 2024, including a compromise of the PyPI package ultralytics in December that delivered a coin miner.

These incidents highlight the evolving tactics of attackers exploiting both open-source repositories and blockchain technology. ReversingLabs researchers warned that developers must carefully vet libraries and maintainers, looking beyond surface metrics such as stars or downloads.

The report concluded that vigilance and stronger package assessment tools are essential to protecting digital assets and development environments.

Source link

Contracts Ethereum exploit Malicious npm Packages Smart
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

CFTC Opens Comment on 24/7 Energy Futures and Perpetual Oil Contracts

June 24, 2026

Cardano’s scaling overhaul hit by a user confidence gap widened by ADA’s slump and wallet exploit

June 24, 2026

US Treasury’s $10B scam warning shows why crypto is racing to police itself

June 24, 2026

SecondFI’s $2M exploit: A wallet flaw leaves Cardano users exposed

June 24, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Why Finland Could be Europe’s Next Crypto Mining Giant

February 22, 2024

Elon Musk’s X Eyes Dismissing Promissory Estoppel Lawsuit: Here’s Everything

December 17, 2023

DOGE Chasing Shiba Inu’s 20% Weekly Surge?

August 14, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Kraken sues crypto derivatives firm PowerTrade over missing funds

June 25, 2026

Dunamu leads seven-firm race for South Korea’s seized crypto custody contract

June 25, 2026

ICE And OKX Tokenized Equities Venture Shows Wall Street Moving On-Chain

June 25, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$59,283.00-2.66%
  • ethereumEthereum(ETH)$1,564.28-4.69%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$551.86-2.91%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.03-3.84%
  • solanaSolana(SOL)$66.28-3.50%
  • tronTRON(TRX)$0.322912-1.77%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.65%
  • HyperliquidHyperliquid(HYPE)$60.880.31%