MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: New Ethereum Smart Contract Malware Discovered
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$77,525.000.38%
  • ethereumEthereum(ETH)$2,309.250.03%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$1.420.84%
  • binancecoinBNB(BNB)$634.160.43%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$85.34-0.10%
  • tronTRON(TRX)$0.3279500.00%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.46%
  • dogecoinDogecoin(DOGE)$0.0972351.84%
Smart Contracts

New Ethereum Smart Contract Malware Discovered

Last updated: September 4, 2025 4:40 pm
Published: 8 months ago
Share

Cybercriminals are evolving, and their latest tactic involves leveraging Ethereum smart contract malware to bypass traditional security measures.

* Ethereum smart contracts are being used to hide malicious URLs, making them harder to detect.

* The malware packages ( and ) were hosted on NPM and appeared legitimate.

* Blockchain traffic is trusted, so security systems often overlook it.

* Fake GitHub repositories were used in a coordinated social engineering campaign.

* This trend marks a shift in malware tactics targeting Web3 infrastructure and open-source software.

How Ethereum Smart Contracts Are Being Exploited

Malicious NPM Packages Uncovered

ReversingLabs researchers revealed that two NPM packages, and published in July 2024, were designed to use Ethereum smart contracts to hide and retrieve URLs associated with malware payloads.

NPM packages ‘colortoolsv2’ & ‘mimelib2’ On GitHub

Source: ReversingLabs

Instead of embedding malicious URLs directly into the packages, the malware fetched command-and-control (C2) server addresses from Ethereum smart contracts, making detection by conventional security tools significantly more difficult.

Why This Technique Works

Because interactions with the Ethereum blockchain are considered legitimate network traffic, querying smart contracts to obtain malware download URLs can go unnoticed by traditional intrusion detection systems.

Once installed, the malicious packages acted as lightweight downloaders, initiating communication with the blockchain to retrieve hidden instructions.

ReversingLabs researcher Lucija Valentić said:

“What is new and different is the use of Ethereum smart contracts to host the URLs where malicious commands are located.”

Social Engineering Meets Blockchain

GitHub Repositories As Deceptive Fronts

These malware packages weren’t isolated threats, they were part of a larger deception campaign. Hackers set up fake GitHub repositories that mimicked legitimate cryptocurrency trading bots.

Tactics used to build trust included:

* Fabricated code commits

* Fake user accounts to simulate popularity

* Multiple maintainer profiles

* Professional-looking documentation

These repositories lured developers into downloading and integrating malicious packages into their projects, unknowingly exposing themselves to malware.

Trolling The Open Source Community

This attack strategy reveals a troubling trend: open-source repositories are becoming attack surfaces.

As developers increasingly rely on packages from NPM, GitHub, and other open repositories, threat actors are embedding themselves in the supply chain.

Not The First, But Definitely The Most Sophisticated

Previous Blockchain Malware Incidents

Ethereum smart contract malware isn’t entirely new. The infamous Lazarus Group, believed to be linked to North Korea, used similar techniques earlier in 2024.

However, this latest approach introduces a new level of stealth and complexity.

Other blockchain ecosystems have also been targeted:

* Solana: A fake GitHub repository posed as a Solana trading bot and delivered obfuscated malware to steal wallet credentials.

* Bitcoinlib: A legitimate Python library used by Bitcoin developers was exploited to inject credential-stealing code.

The Now Deleted Fake GitHub Repository

Source: SlowMist

A Growing Threat To Web3 Security

In 2024 alone, researchers have documented over 23 malicious campaigns targeting crypto-related open-source repositories. This new use of Ethereum smart contract malware shows that attackers are continuously refining their tactics.

Traditional malware detection often assumes that malicious URLs will be hardcoded or fetched from known domains. But by offloading these URLs to the Ethereum blockchain, hackers bypass both static and dynamic analysis.

Valentić warned:

“It highlights the fast evolution of detection evasion strategies by malicious actors who are trolling open source repositories and developers.”

FAQ

What is Ethereum smart contract malware?

Ethereum smart contract malware refers to malicious code or instructions hidden within smart contracts on the Ethereum blockchain, often used to evade detection by traditional cybersecurity tools.

How did the attackers use Ethereum smart contracts in this case?

The attackers embedded URLs inside smart contracts. The infected NPM packages queried the blockchain to fetch these URLs, which were then used to download the actual malware.

Why is this technique effective?

Because blockchain interactions appear legitimate and are often encrypted, they bypass many traditional malware detection methods, including firewalls and URL filtering.

What can developers do to protect themselves?

* Use package auditing tools like Snyk or npm audit

* Verify the credibility of GitHub repositories before use

* Monitor outbound traffic to block unusual blockchain queries

* Keep security software up to date

Is this only happening on Ethereum?

No. Similar tactics have been observed on other blockchains like Solana and Bitcoin, indicating a broader trend across the crypto ecosystem.

Read more on Crypto Weekly

This news is powered by Crypto Weekly Crypto Weekly

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Best Crypto to Buy Now as Global Market Cap Smashes $4 Trillion
Ethereum’s Fusaka fork primed for mainnet after final testnet debut
Will Chainlink’s MegaETH Integration Trigger the Next Big Rally?
SOL pumped 17,100% in 2021; These 3 coins could do the same
As DOGE Wallet Activity Spikes, Could a Non-Meme Altcoin End Up Outperforming Every Meme Coin This Cycle? – South Africa Today

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Trust Wallet Expands Services with Tokenized Stock and ETF Trading
Next Article Ethereum Smart Contracts Become Latest Hiding Spot For Malware | Bitcoinist.com
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d