logo

Ethereum smart contracts used to push malicious code on npm

ID: 4cb17f53-5e30-5255-b2f9-26273ba07d08

STIX ID: report--4cb17f53-5e30-5255-b2f9-26273ba07d08

Feed Name: ReversingLabs Blog

Threat Score
75/100

Date Published: 2025-09-03

Date Updated: 2026-04-29

Author: Lucija Valentić

...
...

ReversingLabs researchers discovered a supply-chain campaign on npm and GitHub where malicious packages (colortoolsv2, mimelib2) used Ethereum smart contracts to hide C2 commands that deliver downloader/second-stage malware; the campaign also employed fake GitHub repositories, fabricated stars/watchers and automated commits to appear legitimate. The report details the technique (smart-contract-hosted commands), the broader GitHub deception infrastructure, observed IOCs, and recommends developers rigorously vet dependencies and maintainers to reduce risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.