Close Menu
Cryphedge.com
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Altcoins
  • Scams
  • Blockchain
  • Regulations
  • Trading
Facebook X (Twitter) Instagram
Cryphedge.com
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Altcoins
  • Scams
  • Blockchain
  • Regulations
  • Trading
Cryphedge.com
Home » Ethereum smart contracts quietly push javascript malware targeting developers
Ethereum smart contracts quietly push javascript malware targeting developers

Ethereum smart contracts quietly push javascript malware targeting developers

September 4, 20253 Mins ReadNo Comments Scams
Share
Facebook Twitter LinkedIn Pinterest Email
Ethereum smart contracts quietly push javascript malware targeting developers

Hackers are using Ethereum smart contracts to conceal malware payloads inside seemingly benign npm packages, a tactic that turns the blockchain into a resilient command channel and complicates takedowns.

ReversingLabs detailed two npm packages, colortoolsv2 and mimelib2, that read a contract on Ethereum to fetch a URL for a second-stage downloader rather than hardcoding infrastructure in the package itself, a choice that reduces static indicators and leaves fewer clues in source code reviews.

The packages surfaced in July and were removed after disclosure. ReversingLabs traced their promotion to a network of GitHub repositories that posed as trading bots, including solana-trading-bot-v2, with fake stars, inflated commit histories, and sock-puppet maintainers, a social layer that steered developers toward the malicious dependency chain.

The downloads were low, but the method matters. Per The Hacker News, colortoolsv2 saw seven downloads and mimelib2 one, which still fits opportunistic developer targeting. Snyk and OSV now list both packages as malicious, providing quick checks for teams auditing historical builds.

History repeating itself

The on-chain command channel echoes a broader campaign that researchers tracked in late 2024 across hundreds of npm typosquats. In that wave, packages executed install or preinstall scripts that queried an Ethereum contract, retrieved a base URL, and then downloaded OS-specific payloads named node-win.exe, node-linux, or node-macos.

Checkmarx documented a core contract at 0xa1b40044EBc2794f207D45143Bd82a1B86156c6b coupled with a wallet parameter 0x52221c293a21D8CA7AFD01Ac6bFAC7175D590A84, with observed infrastructure at 45.125.67.172:1337 and 193.233.201.21:3001, among others.

Phylum’s deobfuscation shows the ethers.js call to getString(address) on the same contract and logs the rotation of C2 addresses over time, a behavior that turns contract state into a movable pointer for malware retrieval. Socket independently mapped the typosquat flood and published matching IOCs, including the same contract and wallet, confirming cross-source consistency.

An old vulnerability continues to thrive

ReversingLabs frames the 2025 packages as a continuation in technique rather than scale, with the twist that the smart contract hosts the URL for the next stage, not the payload.

The GitHub distribution work, including bogus stargazers and chore commits, aims to pass casual due diligence and leverage automated dependency updates within clones of the fake repos.

NemoNemo
Crypto Investor BlueprintCrypto Investor Blueprint

The Crypto Investor Blueprint: A 5-Day Course On Bagholding, Insider Front-Runs, and Missing Alpha

Nice 😎 Your first lesson is on the way.

Please add [email protected] to your email whitelist.

The design resembles earlier use of third-party platforms for indirection, for example GitHub Gist or cloud storage, but on-chain storage adds immutability, public readability, and a neutral venue that defenders cannot easily take offline.

Per ReversingLabs, Concrete IOCs from these reports include the Ethereum contracts 0x1f117a1b07c108eae05a5bccbe86922d66227e2b linked to the July packages and the 2024 contract 0xa1b40044EBc2794f207D45143Bd82a1B86156c6b, wallet 0x52221c293a21D8CA7AFD01Ac6bFAC7175D590A84, host patterns 45.125.67.172 and 193.233.201.21 with port 1337 or 3001, and platform payload names noted above.

Hashes for the 2025 second stage include 021d0eef8f457eb2a9f9fb2260dd2e391f009a21, and for the 2024 wave, Checkmarx lists Windows, Linux, and macOS SHA-256 values. ReversingLabs also published SHA-1s for each malicious npm version, which helps teams scan artifact stores for past exposure.

Protecting against the attack

For defense, the immediate control is to prevent lifecycle scripts from running during install and CI. npm documents the --ignore-scripts flag for npm ci and npm install, and teams can set it globally in .npmrc, then selectively allow necessary builds with a separate step.

The Node.js security best practices page advises the same approach, together with pinning versions via lockfiles and stricter review of maintainers and metadata.

Blocking outbound traffic to the IOCs above and alerting on build logs that initialize ethers.js to query getString(address) provide practical detections that align with the chain-based C2 design.

The packages are gone, the pattern remains, and on-chain indirection now sits alongside typosquats and bogus repos as a repeatable way to reach developer machines.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
cryphedge

Related Posts

How to Stay Safe Before You Hit Send

June 29, 2026

The next big DeFi exploit will start before the code is deployed

May 26, 2026

THORChain exploit turns DeFi halt into trust test

May 16, 2026

Ripple insider warns XRP holders as fake airdrop scams surge across XRPL

May 14, 2026
Add A Comment

Comments are closed.

Editors Picks

Google Gemini AI Predicts Jaw-Dropping Sandisk Stock Price by End of 2026

June 30, 2026

Tom Lee’s BitMine Adds $43 Million in Ethereum as Strategy Pauses Bitcoin Purchases

June 30, 2026

July Bounce, Brutal August, Then the Final Low Near $39,000

June 30, 2026

Binance Will List Re (RE): Everything You Need to Know About the New RWA Token

June 30, 2026
About

cryphedge is an online news portal that aims to share the latest crypto news, bitcoin, altcoin, blockchain, nft news, regulation, trading, crypto scams and much more stuff.

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Bitcoin Price Targets $80,000 as 30-Day Whale Buys Hit 13-Year High?

April 17, 2026

ETH Surpasses $4.3K, Market Cap Flipped Mastercard

August 11, 2025

Should I Sell XRP & Buy Bitcoin Before July 1?

June 23, 2026
Subscribe
Please enable JavaScript in your browser to complete this form.
Loading
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.

  • bitcoinBitcoin(BTC)$58,990.00-0.82%
  • ethereumEthereum(ETH)$1,589.570.43%
  • tetherTether(USDT)$1.000.01%
  • binancecoinBNB(BNB)$550.24-0.39%
  • usd-coinUSDC(USDC)$1.000.01%
  • rippleXRP(XRP)$1.050.44%
  • solanaSolana(SOL)$75.331.67%
  • tronTRON(TRX)$0.316216-0.97%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.01-2.94%
  • HyperliquidHyperliquid(HYPE)$65.39-0.48%
  • dogecoinDogecoin(DOGE)$0.072230-0.14%
  • RainRain(RAIN)$0.015701-1.37%
  • USDSUSDS(USDS)$1.000.01%
  • leo-tokenLEO Token(LEO)$9.26-2.59%
  • stellarStellar(XLM)$0.20370611.42%
  • zcashZcash(ZEC)$399.960.46%
  • WhiteBIT CoinWhiteBIT Coin(WBT)$54.4915.05%
  • moneroMonero(XMR)$312.00-0.26%
  • CantonCanton(CC)$0.1460422.67%
  • cardanoCardano(ADA)$0.1491803.45%
  • chainlinkChainlink(LINK)$7.28-0.06%
  • USD1USD1(USD1)$1.000.01%
  • daiDai(DAI)$1.00-0.04%
  • Ethena USDeEthena USDe(USDE)$1.00-0.01%
  • Gram (prev. Toncoin)Gram (prev. Toncoin)(GRAM)$1.55-2.93%
  • bitcoin-cashBitcoin Cash(BCH)$207.314.11%
  • LABLAB(LAB)$12.10-19.18%
  • litecoinLitecoin(LTC)$42.780.90%
  • Circle USYCCircle USYC(USYC)$1.13-0.06%
  • hedera-hashgraphHedera(HBAR)$0.070346-0.56%
  • Global DollarGlobal Dollar(USDG)$1.000.02%
  • avalanche-2Avalanche(AVAX)$6.691.18%
  • suiSui(SUI)$0.711.85%
  • PayPal USDPayPal USD(PYUSD)$1.000.02%
  • shiba-inuShiba Inu(SHIB)$0.0000040.06%
  • crypto-com-chainCronos(CRO)$0.0539490.65%
  • tether-goldTether Gold(XAUT)$3,970.760.20%
  • nearNEAR Protocol(NEAR)$1.84-0.67%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.13-0.35%
  • BittensorBittensor(TAO)$202.78-1.48%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.058830-0.52%
  • pax-goldPAX Gold(PAXG)$3,973.450.20%
  • uniswapUniswap(UNI)$2.84-0.85%
  • AsterAster(ASTER)$0.630.95%
  • okbOKB(OKB)$79.480.19%
  • OndoOndo(ONDO)$0.3142820.83%
  • HTX DAOHTX DAO(HTX)$0.000002-2.41%
  • WorldcoinWorldcoin(WLD)$0.4140800.15%
  • Falcon USDFalcon USD(USDF)$0.990.04%
  • polkadotPolkadot(DOT)$0.842.54%
  • Ripple USDRipple USD(RLUSD)$1.000.01%
  • usddUSDD(USDD)$1.000.03%
  • mantleMantle(MNT)$0.409062-4.27%
  • aaveAave(AAVE)$86.95-3.09%
  • BFUSDBFUSD(BFUSD)$1.00-0.02%
  • Pi NetworkPi Network(PI)$0.1149050.12%
  • MorphoMorpho(MORPHO)$1.901.43%
  • SkySky(SKY)$0.052746-0.75%
  • internet-computerInternet Computer(ICP)$2.13-1.04%
  • bitget-tokenBitget Token(BGB)$1.60-0.79%
  • ethereum-classicEthereum Classic(ETC)$6.94-1.57%
  • MemeCoreMemeCore(M)$0.8221.79%
  • DeXeDeXe(DEXE)$22.88-0.74%
  • United StablesUnited Stables(U)$1.000.01%
  • AudieraAudiera(BEAT)$3.2816.39%
  • PepePepe(PEPE)$0.000002-0.09%
  • Blockchain CapitalBlockchain Capital(BCAP)$106.970.00%
  • quant-networkQuant(QNT)$64.84-0.59%
  • kucoin-sharesKuCoin(KCS)$6.77-1.88%
  • ​​Stable​​Stable(STABLE)$0.038085-1.33%
  • Spiko EU T-Bills Money Market FundSpiko EU T-Bills Money Market Fund(EUTBL)$1.200.06%
  • Janus Henderson Anemoy Treasury FundJanus Henderson Anemoy Treasury Fund(JTRSY)$1.110.01%
  • Invesco Short Duration US Government Securities FundInvesco Short Duration US Government Securities Fund(USTB)$11.130.03%
  • USDGOUSDGO(USDGO)$1.00-0.02%
  • kaspaKaspa(KAS)$0.0305820.27%
  • cosmosCosmos Hub(ATOM)$1.530.71%
  • render-tokenRender(RENDER)$1.52-1.43%
  • algorandAlgorand(ALGO)$0.083496-2.14%
  • justJUST(JST)$0.0871010.52%
  • POL (ex-MATIC)POL (ex-MATIC)(POL)$0.0697350.55%
  • USDtbUSDtb(USDTB)$1.00-0.03%
  • JupiterJupiter(JUP)$0.2201634.03%
  • nexoNEXO(NEXO)$0.720.05%
  • gatechain-tokenGate(GT)$6.51-0.53%
  • ADIADI(ADI)$5.50-1.19%
  • Janus Henderson Anemoy AAA CLO FundJanus Henderson Anemoy AAA CLO Fund(JAAA)$1.040.02%
  • EthenaEthena(ENA)$0.072243-5.74%
  • VelvetVelvet(VELVET)$1.58-7.42%
  • BeldexBeldex(BDX)$0.084552-5.64%
  • 币安人生 (BinanceLife)币安人生 (BinanceLife)(币安人生)$0.64-8.11%
  • Spiko Amundi Overnight Swap Fund (EUR)Spiko Amundi Overnight Swap Fund (EUR)(EURSAFO)$1.150.06%
  • Venice TokenVenice Token(VVV)$12.72-1.92%
  • GHOGHO(GHO)$1.000.03%
  • Pump.funPump.fun(PUMP)$0.001444-1.24%
  • filecoinFilecoin(FIL)$0.730.95%
  • YLDSYLDS(YLDS)$1.00-0.01%
  • FlareFlare(FLR)$0.006426-1.38%
  • xdce-crowd-saleXDC Network(XDC)$0.027706-1.43%
  • Usual USDUsual USD(USD0)$1.00-0.01%