logo

Ethereum Smart Contracts Abused In Open Source Supply Chain Attack

ID: 21786d15-43a0-5637-ade2-a884d99a3e87

STIX ID: report--21786d15-43a0-5637-ade2-a884d99a3e87

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2025-09-05

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

ReversingLabs researchers discovered a campaign that planted malicious npm packages (colortoolsv2 and mimelib2) which used Ethereum smart contracts to host C2 payload locations; the campaign also leveraged deceptive GitHub repositories (e.g., faux crypto trading bot projects with inflated commits and sock-puppet accounts) to trick developers into installing compromised code, representing a sophisticated software supply-chain attack targeting blockchain/cryptocurrency development ecosystems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.