Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Ethereum unstaking surges 72,000% – Should ETH traders stay cautious?

May 3, 2026

FCA Clears Asset Managers to Run Funds Onchain Under Existing Rules

May 3, 2026

A breakthrough in blockchain property transactions

May 3, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Malicious npm Packages Exploit Ethereum Smart Contracts
Malicious npm Packages Exploit Ethereum Smart Contracts
Security and Privacy

Malicious npm Packages Exploit Ethereum Smart Contracts

September 3, 2025No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A malicious campaign targeting developers through npm and GitHub repositories has been uncovered, featuring an unusual method of using Ethereum smart contracts to conceal command-and-control (C2) infrastructure.

The campaign first came to light in early July when ReversingLabs researcher Karlo Zanki discovered a package named “colortoolsv2” on npm.

The package was quickly removed, but attackers attempted to continue the operation by publishing a duplicate package, “mimelib2.” Both packages deployed a second-stage malware payload through blockchain infrastructure.

What’s New in This Campaign

While malicious npm downloaders appear regularly, these typically contain URLs or scripts embedded in the package itself.

In contrast, colortoolsv2 and mimelib2 leveraged Ethereum smart contracts to store and deliver the URLs used for fetching the second-stage malware. This tactic made detection significantly harder, as the malicious infrastructure was hidden within the blockchain code rather than inside the package files.

“Downloaders are […] published weekly, [but] this use of smart contracts to load malicious commands is something we haven’t seen previously,” RL researchers said.

“It highlights the fast evolution of detection evasion strategies by malicious actors who are trolling open source repositories and developers.”

Read more on smart contract abuse in cybersecurity: Supply Chain Attack Uses Smart Contracts for C2 Ops

GitHub Repositories Disguised as Trading Tools

ReversingLabs investigators also found that the npm packages were tied to a broader campaign across GitHub. Fake repositories, presented as cryptocurrency trading bots, appeared well-established with thousands of commits, multiple maintainers and active watchers.

However, much of this activity was fabricated. According to ReversingLabs, stars and watchers came from accounts created in July, each with minimal activity. Additionally, Puppet accounts acted as maintainers to inflate legitimacy, and forks and commits were used to create the illusion of popularity.

See also  Protocol Village: Spark Protocol Expands Beyond Ethereum to Gnosis

The most prominent example was a repository named “solana-trading-bot-v2,” which bundled the malicious npm package. Although it appeared to be a serious project, closer inspection revealed the network of fake accounts supporting it.

Growing Threats to Open Source

The discovery adds to a growing list of software supply chain attacks targeting crypto-focused developers. 

According to ReversingLabs’s 2025 Software Supply Chain Security report, there were 23 such campaigns in 2024, including a compromise of the PyPI package ultralytics in December that delivered a coin miner.

These incidents highlight the evolving tactics of attackers exploiting both open-source repositories and blockchain technology. ReversingLabs researchers warned that developers must carefully vet libraries and maintainers, looking beyond surface metrics such as stars or downloads.

The report concluded that vigilance and stronger package assessment tools are essential to protecting digital assets and development environments.

Source link

Contracts Ethereum exploit Malicious npm Packages Smart
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Ethereum unstaking surges 72,000% – Should ETH traders stay cautious?

May 3, 2026

Tom Lee’s BitMine secures another 10,000 ether from Ethereum Foundation

May 2, 2026

Digital Asset Security Moves Beyond Keys as Bitgo Adds 5-Layer Checks

May 1, 2026

Ronin Migration to Ethereum Layer 2 on May 12 Transforms Gaming Scalability

May 1, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Warren’s Crypto Bill Is Likely Unconstitutional, It’s Also Unlikely to Pass

December 14, 2023

From Static Credentials to Smart Identity: The Potential of AI-Driven NFTs

July 22, 2025

Volatility Shares to Launch First Solana ETFs in the US

March 20, 2025

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Ethereum unstaking surges 72,000% – Should ETH traders stay cautious?

May 3, 2026

FCA Clears Asset Managers to Run Funds Onchain Under Existing Rules

May 3, 2026

A breakthrough in blockchain property transactions

May 3, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$78,464.000.23%
  • ethereumEthereum(ETH)$2,313.240.38%
  • tetherTether(USDT)$1.000.01%
  • rippleXRP(XRP)$1.390.15%
  • binancecoinBNB(BNB)$618.330.47%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$83.970.03%
  • tronTRON(TRX)$0.3385692.36%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.040.71%
  • dogecoinDogecoin(DOGE)$0.1079660.09%