Wednesday, September 23, 2026
  • Login
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS
CRYPTO MARKETCAP
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS
No Result
View All Result
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse
No Result
View All Result

Ethereum smart contracts quietly push javascript malware targeting developers

by SB Crypto Guru News
September 4, 2025
in Scam Alert
Reading Time: 4 mins read
0 0
A A
0


StakeStake

Hackers are using Ethereum smart contracts to conceal malware payloads inside seemingly benign npm packages, a tactic that turns the blockchain into a resilient command channel and complicates takedowns.

ReversingLabs detailed two npm packages, colortoolsv2 and mimelib2, that read a contract on Ethereum to fetch a URL for a second-stage downloader rather than hardcoding infrastructure in the package itself, a choice that reduces static indicators and leaves fewer clues in source code reviews.

The packages surfaced in July and were removed after disclosure. ReversingLabs traced their promotion to a network of GitHub repositories that posed as trading bots, including solana-trading-bot-v2, with fake stars, inflated commit histories, and sock-puppet maintainers, a social layer that steered developers toward the malicious dependency chain.

The downloads were low, but the method matters. Per The Hacker News, colortoolsv2 saw seven downloads and mimelib2 one, which still fits opportunistic developer targeting. Snyk and OSV now list both packages as malicious, providing quick checks for teams auditing historical builds.

History repeating itself

The on-chain command channel echoes a broader campaign that researchers tracked in late 2024 across hundreds of npm typosquats. In that wave, packages executed install or preinstall scripts that queried an Ethereum contract, retrieved a base URL, and then downloaded OS-specific payloads named node-win.exe, node-linux, or node-macos.

Checkmarx documented a core contract at 0xa1b40044EBc2794f207D45143Bd82a1B86156c6b coupled with a wallet parameter 0x52221c293a21D8CA7AFD01Ac6bFAC7175D590A84, with observed infrastructure at 45.125.67.172:1337 and 193.233.201.21:3001, among others.

Phylum’s deobfuscation shows the ethers.js call to getString(address) on the same contract and logs the rotation of C2 addresses over time, a behavior that turns contract state into a movable pointer for malware retrieval. Socket independently mapped the typosquat flood and published matching IOCs, including the same contract and wallet, confirming cross-source consistency.

An old vulnerability continues to thrive

ReversingLabs frames the 2025 packages as a continuation in technique rather than scale, with the twist that the smart contract hosts the URL for the next stage, not the payload.

The GitHub distribution work, including bogus stargazers and chore commits, aims to pass casual due diligence and leverage automated dependency updates within clones of the fake repos.

NemoNemo
Crypto Investor BlueprintCrypto Investor Blueprint

The Crypto Investor Blueprint: A 5-Day Course On Bagholding, Insider Front-Runs, and Missing Alpha

Nice 😎 Your first lesson is on the way.

Please add [email protected] to your email whitelist.

The design resembles earlier use of third-party platforms for indirection, for example GitHub Gist or cloud storage, but on-chain storage adds immutability, public readability, and a neutral venue that defenders cannot easily take offline.

Per ReversingLabs, Concrete IOCs from these reports include the Ethereum contracts 0x1f117a1b07c108eae05a5bccbe86922d66227e2b linked to the July packages and the 2024 contract 0xa1b40044EBc2794f207D45143Bd82a1B86156c6b, wallet 0x52221c293a21D8CA7AFD01Ac6bFAC7175D590A84, host patterns 45.125.67.172 and 193.233.201.21 with port 1337 or 3001, and platform payload names noted above.

Hashes for the 2025 second stage include 021d0eef8f457eb2a9f9fb2260dd2e391f009a21, and for the 2024 wave, Checkmarx lists Windows, Linux, and macOS SHA-256 values. ReversingLabs also published SHA-1s for each malicious npm version, which helps teams scan artifact stores for past exposure.

Protecting against the attack

For defense, the immediate control is to prevent lifecycle scripts from running during install and CI. npm documents the --ignore-scripts flag for npm ci and npm install, and teams can set it globally in .npmrc, then selectively allow necessary builds with a separate step.

The Node.js security best practices page advises the same approach, together with pinning versions via lockfiles and stricter review of maintainers and metadata.

Blocking outbound traffic to the IOCs above and alerting on build logs that initialize ethers.js to query getString(address) provide practical detections that align with the chain-based C2 design.

The packages are gone, the pattern remains, and on-chain indirection now sits alongside typosquats and bogus repos as a repeatable way to reach developer machines.



Source link

Tags: Bitcoin NewsContractsCrypto NewsCrypto UpdatesDevelopersethereumJavaScriptLatest News on CryptoMalwarepushQuietlySB Crypto Guru NewsSmarttargeting
Previous Post

Best Cryptos to Buy as ChatGPT Predicts $400 Solana By Year’s End

Next Post

Ethereum validator queue shows first staking dominance in months

Related Posts

Uniswap v4 hooks bait DeFi traders with fake swap quotes

by SB Crypto Guru News
September 16, 2026
0

Liquidity aggregator 0x said on Sept. 14 that it had seen an alarming increase in malicious Uniswap v4 hooks over...

The biggest vulnerability in your Bitcoin wallet might be the shipping label

by SB Crypto Guru News
September 12, 2026
0

Hardware wallets might be able to protect your keys, but the paperwork from buying them could expose your identity.To buy...

Attackers exploit fake STM32 vulnerability alert to target Trezor and BitBox holders

by SB Crypto Guru News
September 11, 2026
0

Hardware-wallet makers Trezor and BitBox warned users on Sept. 9 about phishing emails impersonating their brands, urging recipients to avoid...

US hit on $24 billion crypto black market sends rival money launderers running for exits

by SB Crypto Guru News
September 10, 2026
0

US authorities have escalated their crackdown on Xinbi Guarantee, restraining more than $52 million in crypto and seizing key infrastructure.A...

Profit Connect owner convicted over $24M AI crypto fraud scheme

by SB Crypto Guru News
August 26, 2026
0

A federal jury convicted Profit Connect owner Brent C. Kovar on 15 fraud and money-laundering counts after prosecutors said he...

Load More
Next Post
Ethereum validator queue shows first staking dominance in months

Ethereum validator queue shows first staking dominance in months

How I’ve Mastered the Art of Watching Trends to Predict and Create Viral Products — and How You Can, Too

How I've Mastered the Art of Watching Trends to Predict and Create Viral Products — and How You Can, Too

  • Trending
  • Comments
  • Latest

NVIDIA (NVDA) Q2 FY27 Revenue Surges 106% Amid AI Boom

August 26, 2026

Liquid Gets 3,400 BTC Back After On-Chain Talks; White Hats Keep 598.5 BTC

September 7, 2026

Binance Plans Kazakhstan Settlement Hub for CIS and Eastern European Clients

September 7, 2026

TAC Sidechain Halts After Supply Exploit As TON Mainnet Remains Separate

August 25, 2026

Bitcoin Slides As Iran-US Tensions Escalate

September 1, 2026

Bitwise Launches $9B Tokenized Stock Portfolios With Self-Custody and Auto-Rebalancing

August 26, 2026

British Museum bans visitors from photographing Bayeux Tapestry – The Art Newspaper

0

US hit on $24 billion crypto black market sends rival money launderers running for exits

0

XRPL Permission Delegation Begins Final Test for October Activation

0

Sui TVL Holds Above $1B Benchmark As DEX Volume Sustains Momentum

0

Pokerstars Opens Its Player Pool to Rival Brands. Here’s Why

0

Why Your Virtual Event Flopped — and 7 Ways to Make It Better

0

British Museum bans visitors from photographing Bayeux Tapestry – The Art Newspaper

September 23, 2026

Pokerstars Opens Its Player Pool to Rival Brands. Here’s Why

September 23, 2026

Sui TVL Holds Above $1B Benchmark As DEX Volume Sustains Momentum

September 23, 2026

Pi Network Targets 914K Users With Major KYC and Mainnet Migration Fixes

September 23, 2026

From ailing cooling systems to toxic chemicals, a museum tour shines a light on the effects of austerity – The Art Newspaper

September 23, 2026

Binance Buys $100M in Circle Stock, Deepens USDC Alliance

September 23, 2026
Facebook Twitter LinkedIn Tumblr RSS
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse

Find the latest Bitcoin, Ethereum, blockchain, crypto, Business, Fintech News, interviews, and price analysis at SB Crypto Guru News.

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • Mining
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Web3

SITE MAP

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2022 - SB Crypto Guru News.
SB Crypto Guru News is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS

Copyright © 2022 - SB Crypto Guru News.
SB Crypto Guru News is not responsible for the content of external sites.