Business Insights
  • Home
  • Crypto
  • Finance Expert
  • Business
  • Invest News
  • Investing
  • Trading
  • Forex
  • Videos
  • Economy
  • Tech
  • Contact

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • August 2023
  • January 2023
  • December 2021
  • July 2021
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019

Categories

  • Business
  • Crypto
  • Economy
  • Finance Expert
  • Forex
  • Invest News
  • Investing
  • Tech
  • Trading
  • Uncategorized
  • Videos
Apply Loan
Money Visa
Advertise Us
Money Visa
  • Home
  • Crypto
  • Finance Expert
  • Business
  • Invest News
  • Investing
  • Trading
  • Forex
  • Videos
  • Economy
  • Tech
  • Contact
BitMine’s ETH buying spree is clogging Ethereum’s staking pipes: What comes next?
  • Forex

Bad actors are using Ethereum smart contracts to deploy malware: ReversingLabs

  • September 4, 2025
  • Roubens Andy King
Total
0
Shares
0
0
0
Total
0
Shares
Share 0
Tweet 0
Pin it 0

Bad actors have started using Ethereum smart contracts to deploy malicious software and code, and are therefore able to bypass traditional security scans using this novel technique.

Summary

  • The npm packages use Ethereum smart contracts to hide malicious payloads.
  • Researchers believe it is part of a larger campaign that primarily operates through GitHub.

Researchers at ReversingLabs have flagged a new open-source malware that has been deployed across the Node Package Manager (NPM) repository, where it uses obfuscated scripts and smart contracts to fetch command-and-control server URLs that deliver malicious payloads onto compromised systems.

The NPM package repository is a widely used platform for distributing JavaScript libraries and tools. Over the past few years, it has increasingly become a target for software supply chain attacks as hackers are able to trick developers into integrating malicious dependencies into their projects via this method.

According to ReversingLabs, a new strain of open-source malware was found hidden in two npm packages named colortoolsv2 and mimelib2. The packages were found to be using Ethereum smart contracts to remotely load malicious commands and install downloader malware on infected systems.

Both the packages first surfaced in July and function as simple downloaders at first glance. However, instead of directly hosting malicious links, those packages would query the blockchain to fetch URLs when installed.

Subsequently, the retrieved URLs would connect to attacker-controlled command-and-control servers, which then delivered a second-stage payload. Typically, these malicious payloads are designed to exfiltrate sensitive data, install remote access tools, or serve as entry points for a larger attack.

Researchers at ReversingLabs claimed the packages were published as part of a broader campaign targeting open-source ecosystems like npm and GitHub, where attackers relied on social engineering and deceptive project setups to target developers into integrating the malicious code into real-world applications. 

Threat actors have long employed infrastructure-level tactics that are harder to detect. A separate report from ReversingLabs published earlier this year found a trojanized npm package that scanned systems for installed wallets like Atomic and Exodus and silently redirected transactions to attacker-controlled addresses.

Meanwhile, the infamous North Korean hacking group Lazarus was observed deploying its own malicious npm packages earlier this year.

Another incident flagged by security firm Slowmist in 2024 revealed a scam using a malicious Ethereum remote procedure call (RPC) function to deceive users of the imToken wallet.

However, unlike the previous attack vectors, the new campaign discovered by ReversingLabs separates itself by using “ethereum smart contracts to host the URLs where malicious commands are located,” the report noted. 

ReversingLabs urged developers to exercise caution when interacting with npm libraries and third-party packages.

“It is critical for developers to assess each library […] and that means pulling back the covers on both open source packages and their maintainers: looking beyond raw numbers of maintainers, commits, and downloads to assess whether a given package – and the developers behind it – are what they present themselves as.”

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Roubens Andy King

Previous Article
Stock Futures Rise and Bond Selloff Eases Ahead of Jobs Report
  • Investing

Stock Futures Rise and Bond Selloff Eases Ahead of Jobs Report

  • September 4, 2025
  • Roubens Andy King
Read More
Next Article
SEC Reviews Quantum-Safe Roadmap for Digital Assets
  • Crypto

SEC Reviews Quantum-Safe Roadmap for Digital Assets

  • September 4, 2025
  • Roubens Andy King
Read More
You May Also Like
SUI Price To ? Analyst Predicts Altcoin’s Path To New ATH
Read More
  • Forex

SUI Price To $7? Analyst Predicts Altcoin’s Path To New ATH

  • Roubens Andy King
  • September 6, 2025
Tokenizing Car Reservations Can Open Up A Trillion-Dollar Market
Read More
  • Forex

Tokenizing Car Reservations Can Open Up A Trillion-Dollar Market

  • Roubens Andy King
  • September 6, 2025
Ethereum spot ETFs see second-largest outflow surge ever
Read More
  • Forex

Ethereum spot ETFs see second-largest outflow surge ever

  • Roubens Andy King
  • September 6, 2025
Taylor’s Summer Update | Ethereum Foundation Blog
Read More
  • Forex

Taylor’s Summer Update | Ethereum Foundation Blog

  • Roubens Andy King
  • September 6, 2025
Shiba Inu Diamond Hands Are Refusing To Sell, Bulls Eye alt=
Read More
  • Forex

Shiba Inu Diamond Hands Are Refusing To Sell, Bulls Eye $0.00009 ATH

  • Roubens Andy King
  • September 6, 2025
How to Recover a Lost Crypto Wallet Password or Seed Phrase in 2025
Read More
  • Forex

How to Recover a Lost Crypto Wallet Password or Seed Phrase in 2025

  • Roubens Andy King
  • September 6, 2025
BTCC Marketing Executive: Reputation and Research Now Drive Athlete Crypto Deals
Read More
  • Forex

BTCC Marketing Executive: Reputation and Research Now Drive Athlete Crypto Deals

  • Roubens Andy King
  • September 6, 2025
SUI Breakout Structure Builds – Can The Bulls Push Past .50?
Read More
  • Forex

SUI Breakout Structure Builds – Can The Bulls Push Past $3.50?

  • Roubens Andy King
  • September 6, 2025

Recent Posts

  • Who really controls Bitcoin’s price in 2025? Whales, devs or governments, explained
  • SUI Price To $7? Analyst Predicts Altcoin’s Path To New ATH
  • Ripple’s XRP Ledger Just Introduced A Pivotal Update In Its Quest For Dominance
  • Tokenizing Car Reservations Can Open Up A Trillion-Dollar Market
  • Offshore Crypto Exchange’s Won’t Use FBOT Framework To Do Business in US
Featured Posts
  • Who really controls Bitcoin’s price in 2025? Whales, devs or governments, explained 1
    Who really controls Bitcoin’s price in 2025? Whales, devs or governments, explained
    • September 6, 2025
  • SUI Price To ? Analyst Predicts Altcoin’s Path To New ATH 2
    SUI Price To $7? Analyst Predicts Altcoin’s Path To New ATH
    • September 6, 2025
  • Ripple’s XRP Ledger Just Introduced A Pivotal Update In Its Quest For Dominance 3
    Ripple’s XRP Ledger Just Introduced A Pivotal Update In Its Quest For Dominance
    • September 6, 2025
  • Tokenizing Car Reservations Can Open Up A Trillion-Dollar Market 4
    Tokenizing Car Reservations Can Open Up A Trillion-Dollar Market
    • September 6, 2025
  • Offshore Crypto Exchange’s Won’t Use FBOT Framework To Do Business in US 5
    Offshore Crypto Exchange’s Won’t Use FBOT Framework To Do Business in US
    • September 6, 2025
Recent Posts
  • Ethereum spot ETFs see second-largest outflow surge ever
    Ethereum spot ETFs see second-largest outflow surge ever
    • September 6, 2025
  • C++ DEV Update – July edition
    C++ DEV Update – July edition
    • September 6, 2025
  • Taylor’s Summer Update | Ethereum Foundation Blog
    Taylor’s Summer Update | Ethereum Foundation Blog
    • September 6, 2025
Categories
  • Business (2,057)
  • Crypto (1,535)
  • Economy (120)
  • Finance Expert (1,687)
  • Forex (1,534)
  • Invest News (2,359)
  • Investing (1,481)
  • Tech (2,056)
  • Trading (2,024)
  • Uncategorized (2)
  • Videos (811)

Subscribe

Subscribe now to our newsletter

Money Visa
  • Privacy Policy
  • DMCA
  • Terms of Use
Money & Invest Advices

Input your search keywords and press Enter.