Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • DeFi
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • Gaming
  • Legal
    • Taxes & Regulation
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Converter
What's Hot

Crypto Liquidations Nearly at $1B as President Trump Hints at New Trade War With China

October 11, 2025

UK lifts retail ban on crypto ETPs, unlocking access to a £800B market

October 11, 2025

Is Binance Backing Hyperliquid? CZ Breaks Silence, Reveals Founder’s Failed Binance-Backed Project

October 11, 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Buy Crypto NewsBuy Crypto News
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    How The Bitcoin Everything Indicator Improves Bitcoin Price Prediction

    October 11, 2025

    Bitcoin-Focused Metaplanet Suspends Share Rights to Rethink Strategy

    October 10, 2025

    XRP, DOGE, SOL See Friday Pullback as $2.7B Flow to Bitcoin ETFs This Week

    October 10, 2025

    Data Analyst Bitcoin Price Prediction Bombshell

    October 10, 2025

    Grayscale Stakes 857,600 Ethereum Worth $3.83B As Institutional Confidence Grows

    October 10, 2025

    Ethereum Price Loses Key Support, Can Bulls Defend $4,300 Support?

    October 10, 2025

    Ethereum Fusaka Upgrade Set To Redefine ETH Performance — Here’s What to Expect

    October 9, 2025

    Ethereum Price Faces $90 Million Liquidation After Rejection, But Bullish Sentiment Remains Strong

    October 9, 2025

    Crypto Liquidations Nearly at $1B as President Trump Hints at New Trade War With China

    October 11, 2025

    XRP Bullish Symphony: Price And RSI Align For A Run Toward $4

    October 10, 2025

    ZEC, DASH, RAIL See Massive Gains Revives 2018 Crypto ERA

    October 10, 2025

    Ethereum Loses Ground – Further Dips Could Expose Price To Key Support Zone

    October 10, 2025

    Pepe, BMT, CAKE: Crypto Activity Heats Up

    March 18, 2025

    SHIB Burns Over Half a Billion Tokens, Price Surges Over 7%

    March 17, 2025

    DOGE Sees Massive User Growth: Active Addresses Up 400%

    March 15, 2025

    Shiba Inu (SHIB) Price Analysis: Bullish Hints, Bearish Trend

    March 15, 2025

    Crypto Liquidations Nearly at $1B as President Trump Hints at New Trade War With China

    October 11, 2025

    UK lifts retail ban on crypto ETPs, unlocking access to a £800B market

    October 11, 2025

    Is Binance Backing Hyperliquid? CZ Breaks Silence, Reveals Founder’s Failed Binance-Backed Project

    October 11, 2025

    Criminals and Their Networks Hold $75B in Crypto Assets, Says Chainalysis

    October 11, 2025
  • DeFi

    Is Binance Backing Hyperliquid? CZ Breaks Silence, Reveals Founder’s Failed Binance-Backed Project

    October 11, 2025

    What it means for price discovery?

    October 10, 2025

    Sui-based Momentum DEX to hold MMT token sale on Buidlpad

    October 10, 2025

    BNB Meme Coins Crash Up to 95% After CZ Dismisses ‘Endorsement’ Claims

    October 10, 2025

    Coinbase brings DEX trading to US users as CEXs go DeFi

    October 10, 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Criminals and Their Networks Hold $75B in Crypto Assets, Says Chainalysis

    October 11, 2025

    Funton.ai Integrates with U2DPN to Transform GameFi and DePIN Growth

    October 10, 2025

    Gorilla unveils quantum-safe SD-WAN for AI and national security

    October 10, 2025

    Top MIT Researcher Shows Decentralization Could Speed Up Ethereum, Solana

    October 10, 2025

    Bybit Theft Drives Record-Breaking $2bn Haul for North Korea

    October 9, 2025

    Will the UK sell newly seized $7.2B BTC, create Bitcoin treasury or pay victims?

    October 2, 2025

    Crypto hacker falls victim to own scam losing $50 million to Inferno Drainer’s phishing attack

    September 23, 2025

    FileFix Campaign Using Steganography and Multistage Payloads

    September 17, 2025

    Crypto Liquidations Nearly at $1B as President Trump Hints at New Trade War With China

    October 11, 2025

    UK lifts retail ban on crypto ETPs, unlocking access to a £800B market

    October 11, 2025

    Is Binance Backing Hyperliquid? CZ Breaks Silence, Reveals Founder’s Failed Binance-Backed Project

    October 11, 2025

    Criminals and Their Networks Hold $75B in Crypto Assets, Says Chainalysis

    October 11, 2025
  • Web 3
    1. Web3 News
    2. Gaming
    3. View All

    Mixvoip revolutionizes business internet in Luxembourg with 10 Gbit/s XG-PON technology

    October 10, 2025

    NFT Gaming in 2025: The Complete Guide to Blockchain Games

    October 10, 2025

    SOTI Launches New & Improved SOTI Altitude Program for Channel Partners at SOTI SYNC 25

    October 10, 2025

    Sorare Moves to Solana: What It Means for Players and Traders

    October 9, 2025

    The Role of NFTs in Social and Multiplayer Dynamics in Crypto Games

    October 10, 2025

    Tezos Shooter ‘Reaper Actual’ From EverQuest Co-Creator Enters Alpha Playtesting

    October 8, 2025

    Opera and Decrypt Team Up to ‘Bring the Next Billion Users’ to Web3

    October 7, 2025

    UK Council Makes a Bitcoin Windfall from Seized Assets

    October 6, 2025

    Crypto Liquidations Nearly at $1B as President Trump Hints at New Trade War With China

    October 11, 2025

    UK lifts retail ban on crypto ETPs, unlocking access to a £800B market

    October 11, 2025

    Is Binance Backing Hyperliquid? CZ Breaks Silence, Reveals Founder’s Failed Binance-Backed Project

    October 11, 2025

    Criminals and Their Networks Hold $75B in Crypto Assets, Says Chainalysis

    October 11, 2025
  • Legal
    1. Taxes & Regulation
    2. Adoption
    3. View All

    EU to grant ESMA centralized authority over crypto

    October 10, 2025

    Will the Senate’s leaked DeFi bill drain what’s left of US liquidity?

    October 10, 2025

    SEC Excluded Crypto DePIN Tokens From Oversight

    October 10, 2025

    Roger Ver and DOJ reach tentative $48M tax settlement deal

    October 10, 2025

    UK lifts retail ban on crypto ETPs, unlocking access to a £800B market

    October 11, 2025

    BlackRock’s Bitcoin ETF is getting close to $100B milestone

    October 10, 2025

    Ripple targets MENA remittance market with Bahrain alliance

    October 10, 2025

    Luxembourg sets precedent with first eurozone Bitcoin allocation in national fund

    October 10, 2025

    Crypto Liquidations Nearly at $1B as President Trump Hints at New Trade War With China

    October 11, 2025

    UK lifts retail ban on crypto ETPs, unlocking access to a £800B market

    October 11, 2025

    Is Binance Backing Hyperliquid? CZ Breaks Silence, Reveals Founder’s Failed Binance-Backed Project

    October 11, 2025

    Criminals and Their Networks Hold $75B in Crypto Assets, Says Chainalysis

    October 11, 2025
  • Analysis

    Bitcoin Price Teases Below $118k; Here is How to Trade the Tariff War

    October 11, 2025

    Ethereum (ETH) Price Holds Strong at $4,300 as ETF Outflows Test Investor Confidence

    October 10, 2025

    Litecoin Price Breaks Resistance, Can the Rally Rise Above $134?

    October 10, 2025

    Could Stellar Price Retrace More Before Its Next Big Rally To $3?

    October 9, 2025

    How High or Low Can XRP Price Go After the FOMC Meeting Today?

    October 9, 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What is Zcash (ZEC)? The Privacy Coin Using Zero-Knowledge Proofs

    October 8, 2025

    What is the Fusaka Upgrade? Ethereum’s Biggest Scaling Bet Yet

    October 1, 2025

    What Is Aster? The Decentralized Exchange on BNB Chain That’s Taking on Hyperliquid

    September 30, 2025

    What Is Hyperliquid? The Decentralized Exchange With Its Own Blockchain

    September 28, 2025

    Binance Wallet launches meme coin platform with Four.Meme

    October 9, 2025

    Bitcoin exchange withdrawals at three-year low amid ETF surge

    October 8, 2025

    You don’t have to be a coder to understand crypto security

    October 4, 2025

    Robo.ai turns smart cars into economic actors with built-in digital wallet

    October 4, 2025

    Crypto Liquidations Nearly at $1B as President Trump Hints at New Trade War With China

    October 11, 2025

    UK lifts retail ban on crypto ETPs, unlocking access to a £800B market

    October 11, 2025

    Is Binance Backing Hyperliquid? CZ Breaks Silence, Reveals Founder’s Failed Binance-Backed Project

    October 11, 2025

    Criminals and Their Networks Hold $75B in Crypto Assets, Says Chainalysis

    October 11, 2025
  • Tools
    • Market Overview
    • Converter
Buy Crypto NewsBuy Crypto News
Home»Security and Privacy»Ethereum smart contracts quietly push javascript malware targeting developers
Ethereum smart contracts quietly push javascript malware targeting developers
Security and Privacy

Ethereum smart contracts quietly push javascript malware targeting developers

September 4, 2025No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Hackers are utilizing Ethereum smart contracts to hide malware payloads within seemingly harmless npm packages, a strategy that transforms the blockchain into a resilient command channel and complicates takedowns.

Recently, ReversingLabs identified two npm packages, namely colortoolsv2 and mimelib2, which interacted with a contract on Ethereum to retrieve a URL for a second-stage downloader instead of embedding the infrastructure directly in the package. This decision reduces static indicators and makes it harder to detect the malicious intent during source code reviews. Although these packages were discovered in July and promptly removed after disclosure, their promotion was traced back to a network of GitHub repositories posing as trading bots, such as solana-trading-bot-v2. These repositories employed fake stars, inflated commit histories, and puppet maintainers to lure developers into the malicious dependency chain.

Although the number of downloads for these packages was low – colortoolsv2 had seven downloads and mimelib2 had one – the method used by hackers is concerning. Snyk and OSV have now flagged both packages as malicious, allowing teams to quickly identify and remove them from historical builds.

This tactic of using Ethereum contracts to serve as a command channel is not new. In late 2024, researchers observed a similar campaign across numerous npm typosquats. These packages executed scripts that interacted with an Ethereum contract, fetched a base URL, and downloaded OS-specific payloads like node-win.exe, node-linux, or node-macos.

The core contract identified by Checkmarx was linked to a wallet parameter and observed infrastructure at specific IP addresses. Phylum’s deobfuscation revealed the use of ethers.js to query the contract and log the rotation of Command and Control (C2) addresses over time. This behavior effectively turns the contract state into a movable pointer for retrieving malware.

See also  Bitcoin's cool-off results in Ethereum vs. PEPE: Here's why, and who's winning

ReversingLabs views the 2025 packages as a continuation of this technique, with the smart contract now hosting the URL for the next stage of the attack rather than the payload itself. By distributing these packages through GitHub repositories with fake activity, hackers aim to circumvent casual due diligence and exploit automated dependency updates within cloned repositories.

To defend against such attacks, it is crucial to prevent lifecycle scripts from running during install and Continuous Integration (CI). npm offers the –ignore-scripts flag for npm ci and npm install, which can be set globally in .npmrc and selectively allowed for necessary builds. Additionally, following Node.js security best practices, such as pinning versions via lockfiles and conducting thorough reviews of maintainers and metadata, can enhance security measures.

Blocking outbound traffic to known IOCs and monitoring build logs for instances of ethers.js querying getString(address) can help detect and mitigate chain-based C2 attacks. While the malicious npm packages have been removed, the underlying pattern persists, highlighting the need for vigilance against on-chain indirection as a method to target developer environments.

Contracts Developers Ethereum javascript Malware push Quietly smart Targeting
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Ethereum (ETH) Price Holds Strong at $4,300 as ETF Outflows Test Investor Confidence

October 10, 2025

Grayscale Stakes 857,600 Ethereum Worth $3.83B As Institutional Confidence Grows

October 10, 2025

Top MIT Researcher Shows Decentralization Could Speed Up Ethereum, Solana

October 10, 2025

Ethereum Loses Ground – Further Dips Could Expose Price To Key Support Zone

October 10, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Pi Coin, Pepe and Binance Coin (BNB) Prices Aim for Resistance Breakouts

March 16, 2025

Band Protocol Integrates X Layer to Expand Cross-chain Interoperability and Real-World Data Access

December 28, 2024

Ripple vs SEC Lawsuit Not Fully Settled Yet, Say Legal Experts

July 2, 2025
Price Chart


Explore insights on crypto, blockchain, taxes, and security. Stay informed with expert guides, tips, and the latest trends to navigate the digital asset world confidently


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Crypto Liquidations Nearly at $1B as President Trump Hints at New Trade War With China

October 11, 2025

UK lifts retail ban on crypto ETPs, unlocking access to a £800B market

October 11, 2025

Is Binance Backing Hyperliquid? CZ Breaks Silence, Reveals Founder’s Failed Binance-Backed Project

October 11, 2025
Get Informed

Subscribe to Updates

Get the latest creative news From BuyCryptoNews directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 BuyCryptoNews - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.