216.73.216.6

Ethereum smart contracts used to push malicious code on npm

· Published 04/09/2025 00:59 · Modified 04/09/2025 08:18

Export JSON

Essential information

Published
04/09/2025 00:59
Modified
04/09/2025 08:18
Tags
2025-09-04 colortoolsv2 cryptocurrency ethereum mimelib2 npm smart contracts social engineering supply chain attack
Related entities
6 techniques (mitre), 2 malware

Description

A novel technique utilizing was discovered in two packages to conceal malicious commands for installing downloader malware. The packages, and , are part of a larger campaign targeting and GitHub. The attackers created sophisticated GitHub repositories with fake popularity metrics to lure developers. The campaign focused on -related projects, using blockchain technology to evade detection. This incident highlights the evolving strategies of malicious actors in compromising open-source repositories and the need for developers to carefully assess third-party packages before implementation.

External references