Supply Chain Attack Using Ethereum Smart Contracts to Distribute Multi-Platform Malware
Essential information
- Published
- 05/11/2024 17:21
- Modified
- 05/11/2024 18:32
- Tags
- 2024-11-05 blockchain c2 development-tools ethereum jest-fet-mock multi-platform npm smart-contract supply-chain typosquatting
- Related entities
- 4 observables, 11 techniques (mitre), 1 malware, 1 others
Description
A sophisticated supply chain attack has been discovered targeting the NPM ecosystem. The malicious package 'jest-fet-mock' impersonates popular testing utilities and uses Ethereum smart contracts for command-and-control operations. This cross-platform malware affects Windows, Linux, and macOS, executing during package installation via preinstall scripts. It performs info-stealing actions and establishes persistence across infected systems. The attack leverages blockchain technology for resilient C2 infrastructure, making it difficult to detect and take down. This approach represents a notable shift in supply chain attack methodologies, combining blockchain with traditional attack vectors. The campaign specifically targets development environments and CI/CD pipelines, posing a significant threat to software supply chains.