Business Insights
  • Home
  • Crypto
  • Finance Expert
  • Business
  • Invest News
  • Investing
  • Trading
  • Forex
  • Videos
  • Economy
  • Tech
  • Contact

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • August 2023
  • January 2023
  • December 2021
  • July 2021
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019

Categories

  • Business
  • Crypto
  • Economy
  • Finance Expert
  • Forex
  • Invest News
  • Investing
  • Tech
  • Trading
  • Uncategorized
  • Videos
Apply Loan
Money Visa
Advertise Us
Money Visa
  • Home
  • Crypto
  • Finance Expert
  • Business
  • Invest News
  • Investing
  • Trading
  • Forex
  • Videos
  • Economy
  • Tech
  • Contact
BitMine’s ETH buying spree is clogging Ethereum’s staking pipes: What comes next?
  • Forex

Bad actors are using Ethereum smart contracts to deploy malware: ReversingLabs

  • September 4, 2025
  • Roubens Andy King
Total
0
Shares
0
0
0
Total
0
Shares
Share 0
Tweet 0
Pin it 0

Bad actors have started using Ethereum smart contracts to deploy malicious software and code, and are therefore able to bypass traditional security scans using this novel technique.

Summary

  • The npm packages use Ethereum smart contracts to hide malicious payloads.
  • Researchers believe it is part of a larger campaign that primarily operates through GitHub.

Researchers at ReversingLabs have flagged a new open-source malware that has been deployed across the Node Package Manager (NPM) repository, where it uses obfuscated scripts and smart contracts to fetch command-and-control server URLs that deliver malicious payloads onto compromised systems.

The NPM package repository is a widely used platform for distributing JavaScript libraries and tools. Over the past few years, it has increasingly become a target for software supply chain attacks as hackers are able to trick developers into integrating malicious dependencies into their projects via this method.

According to ReversingLabs, a new strain of open-source malware was found hidden in two npm packages named colortoolsv2 and mimelib2. The packages were found to be using Ethereum smart contracts to remotely load malicious commands and install downloader malware on infected systems.

Both the packages first surfaced in July and function as simple downloaders at first glance. However, instead of directly hosting malicious links, those packages would query the blockchain to fetch URLs when installed.

Subsequently, the retrieved URLs would connect to attacker-controlled command-and-control servers, which then delivered a second-stage payload. Typically, these malicious payloads are designed to exfiltrate sensitive data, install remote access tools, or serve as entry points for a larger attack.

Researchers at ReversingLabs claimed the packages were published as part of a broader campaign targeting open-source ecosystems like npm and GitHub, where attackers relied on social engineering and deceptive project setups to target developers into integrating the malicious code into real-world applications. 

Threat actors have long employed infrastructure-level tactics that are harder to detect. A separate report from ReversingLabs published earlier this year found a trojanized npm package that scanned systems for installed wallets like Atomic and Exodus and silently redirected transactions to attacker-controlled addresses.

Meanwhile, the infamous North Korean hacking group Lazarus was observed deploying its own malicious npm packages earlier this year.

Another incident flagged by security firm Slowmist in 2024 revealed a scam using a malicious Ethereum remote procedure call (RPC) function to deceive users of the imToken wallet.

However, unlike the previous attack vectors, the new campaign discovered by ReversingLabs separates itself by using “ethereum smart contracts to host the URLs where malicious commands are located,” the report noted. 

ReversingLabs urged developers to exercise caution when interacting with npm libraries and third-party packages.

“It is critical for developers to assess each library […] and that means pulling back the covers on both open source packages and their maintainers: looking beyond raw numbers of maintainers, commits, and downloads to assess whether a given package – and the developers behind it – are what they present themselves as.”

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Roubens Andy King

Previous Article
Stock Futures Rise and Bond Selloff Eases Ahead of Jobs Report
  • Investing

Stock Futures Rise and Bond Selloff Eases Ahead of Jobs Report

  • September 4, 2025
  • Roubens Andy King
Read More
Next Article
SEC Reviews Quantum-Safe Roadmap for Digital Assets
  • Crypto

SEC Reviews Quantum-Safe Roadmap for Digital Assets

  • September 4, 2025
  • Roubens Andy King
Read More
You May Also Like
Bitcoin Price Must Reclaim 2K to End Consolidation, Prevent Crash
Read More
  • Forex

Bitcoin Price Must Reclaim $112K to End Consolidation, Prevent Crash

  • Roubens Andy King
  • September 4, 2025
Bitcoin Market Base Turns Neutral-Bearish As Flows Stay Weak
Read More
  • Forex

Bitcoin Market Base Turns Neutral-Bearish As Flows Stay Weak

  • Roubens Andy King
  • September 4, 2025
Is Bitcoin About to Start Its Next Bear Market?
Read More
  • Forex

Is Bitcoin About to Start Its Next Bear Market?

  • Roubens Andy King
  • September 4, 2025
Ethereum Open Interest Holds Firm at .4B: Why Traders Aren’t Flinching Despite Price Pressure
Read More
  • Forex

Ethereum Open Interest Holds Firm at $8.4B: Why Traders Aren’t Flinching Despite Price Pressure

  • Roubens Andy King
  • September 4, 2025
Read More
  • Forex

Tom Lee Charts Path To $62,500

  • Roubens Andy King
  • September 4, 2025
Arbitrum kicks off M reward program to boost DeFi growth
Read More
  • Forex

Arbitrum kicks off $40M reward program to boost DeFi growth

  • Roubens Andy King
  • September 4, 2025
Security Alert – Solidity – Variables can be overwritten in storage
Read More
  • Forex

Security Alert – Solidity – Variables can be overwritten in storage

  • Roubens Andy King
  • September 4, 2025
XRP Price Recovery Fails – Is It Doomed for Another Collapse?
Read More
  • Forex

XRP Price Recovery Fails – Is It Doomed for Another Collapse?

  • Roubens Andy King
  • September 3, 2025

Recent Posts

  • Uncle Rate and Transaction Fee Analysis
  • Bitcoin Price Must Reclaim $112K to End Consolidation, Prevent Crash
  • ADP Jobs Report Due As Layoffs Mount, Fed Rate-Cut Odds Rise
  • $375,000 Bitcoin? Market Veteran Says It’s Closer Than You Think
  • Bitcoin Market Base Turns Neutral-Bearish As Flows Stay Weak
Featured Posts
  • Uncle Rate and Transaction Fee Analysis 1
    Uncle Rate and Transaction Fee Analysis
    • September 4, 2025
  • Bitcoin Price Must Reclaim 2K to End Consolidation, Prevent Crash 2
    Bitcoin Price Must Reclaim $112K to End Consolidation, Prevent Crash
    • September 4, 2025
  • ADP Jobs Report Due As Layoffs Mount, Fed Rate-Cut Odds Rise 3
    ADP Jobs Report Due As Layoffs Mount, Fed Rate-Cut Odds Rise
    • September 4, 2025
  • 5,000 Bitcoin? Market Veteran Says It’s Closer Than You Think 4
    $375,000 Bitcoin? Market Veteran Says It’s Closer Than You Think
    • September 4, 2025
  • Bitcoin Market Base Turns Neutral-Bearish As Flows Stay Weak 5
    Bitcoin Market Base Turns Neutral-Bearish As Flows Stay Weak
    • September 4, 2025
Recent Posts
  • Stock Market News for Sep 4, 2025
    Stock Market News for Sep 4, 2025
    • September 4, 2025
  • U.S. Bank Resumes Bitcoin Custody Services For Institutional Investors, Adding Support For Bitcoin ETFs
    U.S. Bank Resumes Bitcoin Custody Services For Institutional Investors, Adding Support For Bitcoin ETFs
    • September 4, 2025
  • Is Bitcoin About to Start Its Next Bear Market?
    Is Bitcoin About to Start Its Next Bear Market?
    • September 4, 2025
Categories
  • Business (2,057)
  • Crypto (1,481)
  • Economy (117)
  • Finance Expert (1,687)
  • Forex (1,479)
  • Invest News (2,358)
  • Investing (1,449)
  • Tech (2,056)
  • Trading (2,024)
  • Uncategorized (2)
  • Videos (808)

Subscribe

Subscribe now to our newsletter

Money Visa
  • Privacy Policy
  • DMCA
  • Terms of Use
Money & Invest Advices

Input your search keywords and press Enter.