logo

Malware found on npm infecting local package with reverse shell

ID: b8c25e0a-05d0-503c-b6c9-96bffe4331c9

STIX ID: report--b8c25e0a-05d0-503c-b6c9-96bffe4331c9

Feed Name: ReversingLabs Blog

Threat Score
78/100

Date Published: 2025-03-26

Date Updated: 2026-04-29

Author: [email protected] (Lucija Valentić)

...
...

This ReversingLabs analysis describes an npm-based malware campaign in which malicious packages (ethers-provider2, ethers-providerz and related packages) download multi-stage payloads, patch locally installed legitimate packages (like ethers and @ethersproject/providers) to insert loader code and a reverse shell connecting to 5.199.166.1, and achieve persistence even after removal of the malicious package; the report includes technical details, a YARA rule for detection, and collected IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.