• News
    • Bitcoin
    • Altcoins
    • Blockchain
    • DeFi
    • Regulation
    • Scams
  • NFT
  • Metaverse
  • Analysis
  • Learn
  • Videos
  • Blogs
  • Market Cap
  • Shop
What's Hot

Survey and Open Talk – Cryptocurrency News & Trading Tips – Crypto Blog by Changelly

2026-05-05

Market overview – May 4, 2026

2026-05-04

Bitcoin Clarity Is Finally Coming

2026-05-03

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

Facebook Twitter Instagram
Crypto Investor News Network
  • News
    • Bitcoin
    • Altcoins
    • Blockchain
    • DeFi
    • Regulation
    • Scams
  • NFT

    Bitcoin Just Hit an All-Time High. Nobody Cares

    2025-09-11

    All Eyes on Art: Upcoming Collections to Watch the Week of May 27

    2025-09-11

    Bitcoin Vegas Belongs to the Suits Now

    2025-09-11

    NFC Summit Lisbon Founder on Evolving the Event and Weathering the Market

    2025-09-11

    All Eyes on Art: Upcoming Collections to Watch the Week of June 3

    2025-09-10
  • Metaverse

    Shib: The Metaverse – Part of the Expanding Shiba Inu Ecosystem

    2025-01-03

    Experience to Earn: Everdome’s Metaverse Frontier

    2024-12-30

    Beyond Bots: Meta Motivo and the Dawn of Humanlike Digital Life

    2024-12-13

    Exploring NetVRk: What Is Behind This AI-Driven Virtual Universe?

    2024-10-28

    Council of Europe Highlights Metaverse’s Impact on Privacy and Democracy

    2024-09-05
  • Analysis

    Crypto Exchange Coinbase Lists New DeFi Altcoin Project Built on Base Blockchain

    2023-12-13

    Ethereum Price Bears Keep Pushing, Why Decline Isn’t Over Yet

    2023-12-13

    Trader Bullish on Cosmos (ATOM), Says One Dogecoin Rival Setting Up for Next Leg Up – Here’s His Outlook

    2023-12-13

    AVAX Price Pumps 50% and Dumps 15%, Why Uptrend Is Still Strong

    2023-12-13

    Top Trader Predicts Parabolic Rally for Solana Competitor – Here’s His Upside Target

    2023-12-13
  • Learn

    Survey and Open Talk – Cryptocurrency News & Trading Tips – Crypto Blog by Changelly

    2026-05-05

    Market overview – May 4, 2026

    2026-05-04

    What Are Crypto Derivatives? Futures, Perpetuals, and Options Made Easy

    2026-03-18

    What Happens If Bitcoin Crashes to Zero?

    2026-03-18

    What Is Contract Trading in Crypto and How Does It Work?

    2026-03-11
  • Videos

    Bitcoin Clarity Is Finally Coming

    2026-05-03

    Tether Is Building A Bitcoin EMPIRE

    2026-04-30

    This DeFi Giant Is COLLAPSING. Your Crypto Might Be Next!

    2026-04-22

    Why I Think a Bitcoin Pump is Coming…

    2026-04-19

    How to Trade VOL, Timing Time, TAMs & Margin Traps 🚨

    2026-04-12
  • Blogs
  • Market Cap
  • Shop
Facebook Twitter Instagram TikTok
Crypto Investor News Network
Home»Scams»Ethereum smart contracts quietly push javascript malware targeting developers
Scams

Ethereum smart contracts quietly push javascript malware targeting developers

2025-09-04No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Ethereum smart contracts quietly push javascript malware targeting developers
Share
Facebook Twitter LinkedIn Pinterest Email

Hackers are using Ethereum smart contracts to conceal malware payloads inside seemingly benign npm packages, a tactic that turns the blockchain into a resilient command channel and complicates takedowns.

ReversingLabs detailed two npm packages, colortoolsv2 and mimelib2, that read a contract on Ethereum to fetch a URL for a second-stage downloader rather than hardcoding infrastructure in the package itself, a choice that reduces static indicators and leaves fewer clues in source code reviews.

The packages surfaced in July and were removed after disclosure. ReversingLabs traced their promotion to a network of GitHub repositories that posed as trading bots, including solana-trading-bot-v2, with fake stars, inflated commit histories, and sock-puppet maintainers, a social layer that steered developers toward the malicious dependency chain.

The downloads were low, but the method matters. Per The Hacker News, colortoolsv2 saw seven downloads and mimelib2 one, which still fits opportunistic developer targeting. Snyk and OSV now list both packages as malicious, providing quick checks for teams auditing historical builds.

History repeating itself

The on-chain command channel echoes a broader campaign that researchers tracked in late 2024 across hundreds of npm typosquats. In that wave, packages executed install or preinstall scripts that queried an Ethereum contract, retrieved a base URL, and then downloaded OS-specific payloads named node-win.exe, node-linux, or node-macos.

Checkmarx documented a core contract at 0xa1b40044EBc2794f207D45143Bd82a1B86156c6b coupled with a wallet parameter 0x52221c293a21D8CA7AFD01Ac6bFAC7175D590A84, with observed infrastructure at 45.125.67.172:1337 and 193.233.201.21:3001, among others.

Phylum’s deobfuscation shows the ethers.js call to getString(address) on the same contract and logs the rotation of C2 addresses over time, a behavior that turns contract state into a movable pointer for malware retrieval. Socket independently mapped the typosquat flood and published matching IOCs, including the same contract and wallet, confirming cross-source consistency.

See also  Jan 2024 SEC’s X account hacker got 14 months in prison for cyber fraud

An old vulnerability continues to thrive

ReversingLabs frames the 2025 packages as a continuation in technique rather than scale, with the twist that the smart contract hosts the URL for the next stage, not the payload.

The GitHub distribution work, including bogus stargazers and chore commits, aims to pass casual due diligence and leverage automated dependency updates within clones of the fake repos.

Crypto Investor Blueprint

The Crypto Investor Blueprint: A 5-Day Course On Bagholding, Insider Front-Runs, and Missing Alpha

Nice 😎 Your first lesson is on the way.

Please add [email protected] to your email whitelist.

The design resembles earlier use of third-party platforms for indirection, for example GitHub Gist or cloud storage, but on-chain storage adds immutability, public readability, and a neutral venue that defenders cannot easily take offline.

Per ReversingLabs, Concrete IOCs from these reports include the Ethereum contracts 0x1f117a1b07c108eae05a5bccbe86922d66227e2b linked to the July packages and the 2024 contract 0xa1b40044EBc2794f207D45143Bd82a1B86156c6b, wallet 0x52221c293a21D8CA7AFD01Ac6bFAC7175D590A84, host patterns 45.125.67.172 and 193.233.201.21 with port 1337 or 3001, and platform payload names noted above.

Hashes for the 2025 second stage include 021d0eef8f457eb2a9f9fb2260dd2e391f009a21, and for the 2024 wave, Checkmarx lists Windows, Linux, and macOS SHA-256 values. ReversingLabs also published SHA-1s for each malicious npm version, which helps teams scan artifact stores for past exposure.

Protecting against the attack

For defense, the immediate control is to prevent lifecycle scripts from running during install and CI. npm documents the --ignore-scripts flag for npm ci and npm install, and teams can set it globally in .npmrc, then selectively allow necessary builds with a separate step.

See also  Low-Cap Ethereum Competitor Skyrockets by 61% This Week Amid Flurry of Futures Contract Listings

The Node.js security best practices page advises the same approach, together with pinning versions via lockfiles and stricter review of maintainers and metadata.

Blocking outbound traffic to the IOCs above and alerting on build logs that initialize ethers.js to query getString(address) provide practical detections that align with the chain-based C2 design.

The packages are gone, the pattern remains, and on-chain indirection now sits alongside typosquats and bogus repos as a repeatable way to reach developer machines.

Contracts developers Ethereum javascript malware Push Quietly Smart Targeting
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Ethereum Crypto Price Analysis – is ETH Still Worth It?

2026-03-11

DOJ seizures of $580M expose how crypto investment scams scaled into shift work with quotas and scripts

2026-03-03

Vitalik Buterin Is Selling His ETH: What It Means for Ethereum

2026-03-01

HUGE ETHEREUM CRASH – Will ETH Go Back to $1,400?

2026-02-25
Add A Comment

Leave A Reply Cancel Reply

Top Posts
DeFi

Binance integrates Curve (CRV) on Arbitrum One and Optimism

2024-06-12

The exciting news for the DeFi community is that Binance has easily integrated Curve Finance’s…

Blockchain

Family Offices Are Warming Up to Blockchain and Crypto

2023-12-21

A report issued by Grant Thornton, a professional services network, has revealed that family offices…

Analysis

Tezos (XTZ) Loses Steam In Q2, Market Cap Drops 30% Following SEC Crackdown

2023-07-25

According to a recent report by crypto research firm Messari, Tezos has been progressing in…

Subscribe to Updates

Get the latest news and Update from CINN about Crypto, Metaverse and NFT.

Editors Picks

Survey and Open Talk – Cryptocurrency News & Trading Tips – Crypto Blog by Changelly

2026-05-05

Market overview – May 4, 2026

2026-05-04

Bitcoin Clarity Is Finally Coming

2026-05-03

Tether Is Building A Bitcoin EMPIRE

2026-04-30
Crypto Investor News Network
Facebook Twitter Instagram TikTok
  • Contact
  • Terms & Conditions
  • Privacy Policy
  • DMCA
  • Disclouser
© 2026 - All rights are reserved.

Type above and press Enter to search. Press Esc to cancel.

bitcoin
Bitcoin (BTC) $ 81,634.00
ethereum
Ethereum (ETH) $ 2,382.43
tether
Tether (USDT) $ 0.999916
xrp
XRP (XRP) $ 1.42
bnb
BNB (BNB) $ 633.33
usd-coin
USDC (USDC) $ 0.999863
solana
Solana (SOL) $ 86.61
tron
TRON (TRX) $ 0.344203
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
staked-ether
Lido Staked Ether (STETH) $ 2,265.05