MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Cybercriminals Use Ethereum Smart Contracts in Malicious npm Packages – 36Crypto
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$68,931.004.60%
  • ethereumEthereum(ETH)$2,047.255.85%
  • tetherTether(USDT)$1.000.03%
  • rippleXRP(XRP)$1.414.04%
  • binancecoinBNB(BNB)$620.031.35%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$84.528.61%
  • tronTRON(TRX)$0.2818800.75%
  • dogecoinDogecoin(DOGE)$0.0966114.44%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.68%
Smart Contracts

Cybercriminals Use Ethereum Smart Contracts in Malicious npm Packages – 36Crypto

Last updated: September 4, 2025 8:10 pm
Published: 5 months ago
Share

Cybercriminals exploit Ethereum smart contracts to bypass npm security measures. Fraudulent GitHub repositories deceive developers into downloading malicious npm packages. Increasing sophistication of open-source attacks highlights growing blockchain security threats.

Cybercriminals have recently developed a new method for bypassing detection in malicious npm packages by utilizing Ethereum smart contracts. As revealed by software security firm ReversingLabs, this is a drastic change in the way threat actors use open-source tools to attack developers. The attack also uses smart contracts to conceal command-and-control (C2) instructions, which complicates the detection and suppression of the threat by security systems.

As part of the campaign, two npm packages were created, one called colortoolsv2 and the other called mimetoolib2. These malicious packages fetch C2 URLs of Ethereum on-chain contracts, which redirect the system to a second-stage downloader. Rather than placing links in the package code itself, the attackers invoke an obfuscated script that requests the Ethereum contract to tell it where the following payload is. This approach makes it harder to detect and eliminate, a new and daunting strategy for security specialists.

Also Read: Shiba Inu Burn Rate Surges, But Impact on Price Remains Unclear

Fake Repositories and Developer Trust Exploited

To further their efforts, cybercriminals used fraudulent, crypto-themed GitHub repositories to gain the trust of developers. These repositories looked valid, with overrated stars and autogenerated commit histories, inviting developers to push the malicious npm packages to their projects. Once integrated, the malicious code might run undetected, thus exposing sensitive data and assets.

ReversingLabs’ probe discovered that the campaign was a subset of an even bigger scheme to infect npm and GitHub with malicious repositories. These were often presented as crypto trading bots or other useful tools, misleading developers into downloading harmful dependencies.

A Growing Trend in Open-Source Attacks

This attack is part of a broader trend of increasing sophistication in cyberattacks targeting open-source platforms like npm and GitHub. Past campaigns used tricks such as artificial repositories with false activity to fool developers.

Threat is a bare reality of the increasing use of blockchain in malicious code. It emphasizes that developers should be on guard against emerging tactics that are used to compromise open-source trust. While these malicious packages have been removed from npm, the evolving nature of these attacks calls for continued vigilance to protect the integrity of the open-source ecosystem.

Also Read: John Deaton Highlights XRP Army’s Key Role in Ripple’s SEC Win

Related

Read more on 36Crypto

This news is powered by 36Crypto 36Crypto

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Daylight Airdrop Guide | Step-by-step Guide
Stellar and the Stablecoin Moment: Infrastructure for Enterprise-Grade Payments
Ripple Integrates Wormhole NTT for $RLUSD Multichain Expansion
DEALMining user scale exceeds 6.8 million, launching global free cloud mining reward activities
Best Low-Cap Meme Coin Hunt: Layer Brett Tops Lists for Potential to Rival Dogecoin’s Legendary Rise

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Hackers Using Ethereum Smart Contracts to Deliver Malware: Report – Decrypt
Next Article Bitcoin’s Fate Above $120K Now Hinges On Fed Rate Cuts, Not Cypherpunk Ideals
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d