Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

EToro reports second quarter crypto loss even as total profit beats estimates

August 11, 2026

Pump.fun: Why PUMP’s $2.97B volume surge faces THIS supply test

August 11, 2026

Stolen Bitcoin at Center of Kidnapping Plot, 3 Face 20 Years

August 11, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Six npm Packages Read C2 Addresses From Ethereum Wallet
Six npm Packages Read C2 Addresses From Ethereum Wallet
Security and Privacy

Six npm Packages Read C2 Addresses From Ethereum Wallet

August 11, 2026No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Six npm packages have been found querying an attacker-controlled Ethereum wallet to work out where to fetch their next stage of malware, reading command-and-control (C2) addresses out of a blockchain transaction.

Sonatype Research Labs identified the packages on August 10 and published its analysis the same day. All six carry the same payload, and Sonatype is tracking them as sonatype-2026-005899 and sonatype-2026-005901.

The wallet address matches one documented by researchers at OpenSourceMalware, who named the technique NullReceiver and attributed the activity they examined to the DPRK-linked Contagious Interview campaign, associated with the Lazarus group. 

Sonatype said it confirmed the wallet match and observed similar tradecraft, including package hijacking and blockchain-based retrieval of follow-on infrastructure.

Read more on npm supply chain attacks: North Korean Hackers Launch New Wave of npm Package Attacks

A Transaction as a Dead Drop

On execution, the loader queried Ethereum for an outbound transaction from the wallet and read bytes out of the transaction’s recipient address. Those bytes decoded into two IPv4 addresses, which it treated as primary and secondary C2 endpoints.

Sonatype found this implementation more extensive than the behavior previously documented. The loader could query several Ethereum remote procedure call providers, race requests between them, batch its calls and fall back to the Blockscout API to locate the relevant transaction, giving it multiple routes to recover its infrastructure if one failed.

Once resolved, it pulled two further stages from the server. If a standard request failed, it retried and recovered the payload from a response header instead.

The result was decoded and could either run directly inside the current Node.js process or launch as a detached child process.

See also  Cronos broadens scaling roadmap from Cosmos to Ethereum

Two Routes Into the Registry

The six split evenly between hijacked packages and purpose-built ones. Three appearED to be legitimate packages whose publishing accounts were compromised: @kolbo/mcp, agentgui and godot-kit.

In each, the original functionality remained intact and the loader was appended to the end of an existing file, which Sonatype noted matched behaviour it observed in the DPRK-linked PolinRider campaign.

The other three, envpack-conf, postcss-initial-provider and tailwindcss-motion-advanced, were published with the malware already present, each wrapped in plausible functionality. One carried package-configuration code, another a working PostCSS plugin and the third hid the loader inside a minified utility file.

Sonatype said the hijacked packages presented the harder detection problem, because the malicious code arrived through names developers may already recognize and trust.

Teams should check their environments for the affected versions, remove them and investigate for follow-on JavaScript execution or other signs of compromise. Sonatype said it is continuing to examine related npm activity.

Source link

addresses Ethereum npm Packages read wallet
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Bitcoin address sent $423M via Binance-attributed wallet

August 11, 2026

North Korea’s Kimsuky Turns AI Into a Crypto Hacking Weapon

August 11, 2026

NeoFS S3 Gateway v0.45.1 optimizes read, write performance via SDK RC21

August 11, 2026

US Sanctions Iranian $6bn Crypto “Exchange” Shelbit

August 10, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

SPACE ID Launches New Function To Help Users Sell Domain Names At Custom Prices

May 30, 2023

Bitcoin difficulty falls to 135.59T – But THESE 3 miner signals warn of stress

April 20, 2026

What Happened Yesterday? The Market Rallied, Then Dumped — All Within a Few Hours…

June 13, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

EToro reports second quarter crypto loss even as total profit beats estimates

August 11, 2026

Pump.fun: Why PUMP’s $2.97B volume surge faces THIS supply test

August 11, 2026

Stolen Bitcoin at Center of Kidnapping Plot, 3 Face 20 Years

August 11, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$63,292.00-0.40%
  • ethereumEthereum(ETH)$1,862.45-0.30%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$608.932.00%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.01-0.40%
  • solanaSolana(SOL)$75.22-0.60%
  • tronTRON(TRX)$0.3349691.20%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.021.50%
  • HyperliquidHyperliquid(HYPE)$54.06-0.50%