Close Menu
ItsDailyCrypto.comItsDailyCrypto.com
  • Advertise
  • Home
  • Bitcoin
  • Altcoins
  • VeChain
  • Cardano
  • Ethereum
  • NFTs
  • Ripple
  • Solana
  • Log In
ItsDailyCrypto.comItsDailyCrypto.com
  • Home
  • Bitcoin
  • Ethereum
  • Solana
  • Cardano
  • Ripple
  • VeChain
  • Altcoin
  • NFTs
ADVERTISE
  • Log In
ItsDailyCrypto.comItsDailyCrypto.com
Home»Ethereum»ReversingLabs: Bad actors use Ethereum smart contracts for malware deployment

ReversingLabs: Bad actors use Ethereum smart contracts for malware deployment

Ethereum By Gavin04/09/2025
Facebook Twitter LinkedIn Email
BTC loses favor, assets under management reach new all-time high
BTC loses favor, assets under management reach new all-time high
Share
Facebook Twitter LinkedIn Email

By using Ethereum smart contracts, bad actors can now deploy malware and malicious code without having to go through traditional security scanning.

The following is a summary of the information that you will find on this page.

  • The packages use Ethereum Smart Contracts to disguise malicious payloads.
  • Researchers suspect that it may be part of a wider campaign which mainly operates via GitHub.

ReversingLabs has conducted research on the effects of a variety of drugs. flagged a new malware open source that was deployed in the Node Package Manager repository. It uses smart contracts, obfuscated code and cryptic scripts to get command-and-control URLs which deliver malicious payloads into compromised systems.

NPM’s package repository has become a popular platform to distribute JavaScript libraries, tools and other software. It has been increasingly targeted by software supply-chain attacks in recent years as hackers have learned to use this technique to convince developers that they need malicious dependencies for their project.

ReversingLabs has discovered a new open-source malware strain hidden within two npm package names colortoolsv2 & mimelib2. According to ReversingLabs, the packages use Ethereum smart contracts for remotely loading malicious commands and installing downloader malware onto infected machines.

Initially, both packages appear as simple downloaders. Instead of hosting malicious links directly, these packages will query the blockchain when installed to fetch URLs.

Subsequently the URLs were used to link up with attacker-controlled servers which delivered a secondary payload. These malicious payloads typically aim to steal sensitive information, download remote access software, or act as an entry point for larger attacks.

ReversingLabs’ researchers claimed that these packages were part of a broader attack targeting open-source communities like npm, GitHub and others. Attackers used deceptive setups and social engineering to lure developers into integrating this malicious code in real-world apps. 

Infrastructure-level threats have been around for a long time. ReversingLabs has released a separate report. published A trojanized package of npm was discovered earlier this year that silently redirects transactions from attacker-controlled accounts to wallets such as Atomic, Exodus or Atomic.

Lazarus, an infamous North Korean hacking team was arrested in the meantime observed It deployed malicious npm-packages earlier this year.

Slowmist flags another crime in 2024 revealed A scam that uses a malicious Ethereum RPC function to trick users of imToken’s wallet.

ReversingLabs has discovered a new attack vector that is different from the others. “ethereum smart contracts to host the URLs where malicious commands are located,” Noted in the report 

ReversingLabs warned developers against interacting with third-party libraries or npm.

“It is critical for developers to assess each library […] and that means pulling back the covers on both open source packages and their maintainers: looking beyond raw numbers of maintainers, commits, and downloads to assess whether a given package – and the developers behind it – are what they present themselves as.”

“This article is not financial advice.”

“Always do your own research before making any type of investment.”

“ItsDailyCrypto is not responsible for any activities you perform outside ItsDailyCrypto.”

Source: crypto.news

act AR c ETH ethe Ether Ethereu ethereum EU LA RSI S SMA Smart Contract Smart Contracts US w war
Share. Facebook Twitter LinkedIn Email
Avatar
Gavin

Related Posts

Ethereum Price hits Week Low April 28

28/04/2026

Sharplink increases stakes in Ethereum

28/04/2026

Ethereum Drops as Whales Transfer $100 Million of ETH to Exchanges

28/04/2026

Is Bitcoin quantum-safe? Complete guide to 2026

28/04/2026
Top News

SEI surges 19% after Binance validation — 3 metrics hint at a push toward $0.23

Just in: US Stock Market erases its losses and turns green…

Arizona Governor vetoes Bill to Make Bitcoin Part of State Reserves

Microstrategy Boosts Bitcoin Holdings To 205,000 BTC Following $800 Million Capital Raising

Bitcoin Key Transferring Averages Point out An Imminent Drop To $38,000

Load More

Welcome to itsDailyCrypto.com – your destination for the latest updates and insights from the world of cryptocurrencies and blockchain technology. Whether you're a seasoned investor or just beginning your journey into the realm of digital assets, we're here to keep you informed and engaged. Stay tuned for the most current news, trends, and expert analysis to navigate the ever-evolving landscape of crypto.

We're social. Connect with us:

X (Twitter) Instagram
Categories
  • Home
  • Bitcoin
  • Ethereum
  • Solana
  • Cardano
  • Ripple
  • VeChain
  • Altcoin
  • NFTs
Top Insights

John Koudounis and Eric Trump Call Bitcoin a Global Reserve Asset; Float a $1M Price Goal

30/04/2026

Crypto investors think Bitcoin is undervalued by more than 70%

30/04/2026
X (Twitter) Instagram
  • About us
  • Contact
  • Privacy Policy
  • Advertise
© 2026 Itsdailycrypto.com. Powered by Zwijberg

Type above and press Enter to search. Press Esc to cancel.

solana
Solana (SOL) $ 83.14
bitcoin
Bitcoin (BTC) $ 76,060.00
ethereum
Ethereum (ETH) $ 2,257.45
bnb
BNB (BNB) $ 616.92
dogecoin
Dogecoin (DOGE) $ 0.106793
xrp
XRP (XRP) $ 1.37
vechain
VeChain (VET) $ 0.00705
world-mobile-token
World Mobile Token (WMTX) $ 0.062112
cardano
Cardano (ADA) $ 0.246752
shiba-inu
Shiba Inu (SHIB) $ 0.000006
chainlink
Chainlink (LINK) $ 9.12
hackenai
Hacken (HAI) $ 0.002852
hapi
HAPI (HAPI) $ 0.423969
gala
GALA (GALA) $ 0.003243