Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Attackers Exploit Ethereum Smart Contracts in Supply Chain Breach

Attackers Exploit Ethereum Smart Contracts in Supply Chain Breach

Rogue npm packages and fake GitHub repos used to spread malware

Kelly Cromley by Kelly Cromley
Sep 4, 2025
in Ethereum News, Market News, News
Reading Time: 3 mins read
0
Ethereum

A recent cybersecurity incident has revealed how attackers combined blockchain technology with traditional software repositories to execute a supply chain attack. According to research by ReversingLabs, the threat actors involved deployed rogue npm packages and manipulated GitHub repositories, using Ethereum smart contracts to conceal malware payloads. The campaign is believed to have primarily targeted developers and users in the cryptocurrency sector.

A Shift in Attack Techniques

The researchers highlighted that the incident reflected a growing sophistication in repository-based attacks. They noted that attackers were increasingly attempting to implant malicious code into legitimate applications, with the dual objectives of stealing sensitive development assets and exfiltrating digital resources.

The investigation showed that the attackers utilized Ethereum smart contracts to hide URLs containing secondary malware payloads. This tactic likely helped them evade detection from automated security tools that scan npm packages for suspicious links or commands.

Discovery of Rogue npm Packages

In July, ReversingLabs identified two malicious npm packages named colortoolsv2 and mimelib2. These were found to leverage Ethereum smart contracts for delivering malware. Interestingly, the packages did not make significant efforts to appear legitimate or attractive to developers, which is the usual approach in supply chain compromises. Instead, the researchers concluded that these packages were only one part of a broader coordinated scheme.

Both colortoolsv2 and mimelib2 contained only the files required to perform their malicious tasks. Their primary role was to act as dependencies for fake GitHub repositories that unsuspecting users were tricked into running. Once executed, these repositories would automatically download the rogue npm packages.

Fake GitHub Repositories Crafted to Deceive

The malicious GitHub projects were disguised as automated cryptocurrency trading bots. They appeared convincing by showcasing thousands of code commits, multiple stars, and numerous active contributors. However, deeper analysis revealed that the activity was fabricated.

The accounts behind the commits were sockpuppets, all created around the same period as the npm packages. The inflated activity gave the false impression of legitimacy. ReversingLabs discovered that most commits involved repetitive modifications to the project’s LICENSE file, while genuine changes were limited to code that executed and downloaded the rogue npm dependencies.

⚠️ New RL threat research: 2 malicious #npm packages abuse #Ethereum smart contracts to load #malware on compromised devices. https://t.co/wzDRKfm2yh

— ReversingLabs (@ReversingLabs) September 3, 2025


The researchers observed that the infrastructure used for these commits appeared automated, with thousands being added daily, signaling a well-orchestrated attempt to maintain the illusion of an active development community.

Use of Ethereum for Malware Delivery

The malicious npm packages included code that connected to the Ethereum blockchain. While such a feature might not immediately appear suspicious in a cryptocurrency-related library, its actual purpose was to retrieve hidden URLs stored in Ethereum smart contracts. These URLs then facilitated the download of malware payloads. Smart contracts, which are small programs executed automatically on the blockchain, were thus repurposed as a tool to distribute malicious links covertly.

Lessons for Developers

The campaign underscored the importance of rigorous due diligence when integrating open-source software into projects. Researchers stressed that developers should evaluate not just the raw statistics of a package—such as contributor counts, number of commits, or download volumes—but also verify the authenticity of maintainers and their contributions.

This case has been seen as a warning to the broader development community that supply chain threats are evolving rapidly. With attackers blending blockchain tools and repository manipulation, developers are urged to adopt a deeper level of scrutiny before incorporating third-party libraries into their workflows.

Previous Post

Ondo Finance Opens Tokenized Access to U.S. Stocks

Next Post

Trimont Taps JPMorgan’s Kinexys for Faster Real Estate Payments

Related Posts

agi open network

AON and Infiblue World Unite to Advance AI-Driven Web3 Social Tools

by Kelly Cromley
Dec 5, 2025
0

AGI Open Network (AON), a prominent decentralized ecosystem for building AI agents, has entered a strategic partnership with Infiblue World,...

N3XT

Blockchain-Driven N3XT Bank Promises Instant 24/7 Dollar Payments

by Kelly Cromley
Dec 4, 2025
0

A new player in financial services, N3XT, has formally launched with the goal of reshaping business-to-business payments through blockchain technology....

chaingpt

ChainGPT Integrates Into Carbon Browser to Simplify Web3 Access

by Kelly Cromley
Dec 4, 2025
0

ChainGPT and Carbon Browser have jointly rolled out a browser-level AI assistant that both teams describe as a meaningful upgrade...

my-green-condo

MGCOne Patent Signals a Major Shift in Community Management

by Kelly Cromley
Dec 4, 2025
0

My Green Condo Inc. reported that the United States Patent and Trademark Office has awarded U.S. Patent No. 12443952 for...

digivolt

Digivolt Introduces Tokenized Access to Clean-Energy Production

by Kelly Cromley
Dec 4, 2025
0

Digivolt, a developing Web3 clean-energy infrastructure initiative, announced the rollout of its blockchain-powered energy token aimed at making participation in...

Supra

Supra Unveils Hydrangea++ to Push Blockchain Toward Physical Speed Limits

by Kelly Cromley
Dec 4, 2025
0

Supra, the first MultiVM Layer-1 blockchain built for what it describes as Automatic DeFi, has introduced Hydrangea++, an upgraded version...

Next Post
trimont

Trimont Taps JPMorgan’s Kinexys for Faster Real Estate Payments

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

agi open network
Market News

AON and Infiblue World Unite to Advance AI-Driven Web3 Social Tools

by Kelly Cromley
Dec 5, 2025
N3XT
Market News

Blockchain-Driven N3XT Bank Promises Instant 24/7 Dollar Payments

by Kelly Cromley
Dec 4, 2025
chaingpt
Market News

ChainGPT Integrates Into Carbon Browser to Simplify Web3 Access

by Kelly Cromley
Dec 4, 2025
my-green-condo
Market News

MGCOne Patent Signals a Major Shift in Community Management

by Kelly Cromley
Dec 4, 2025
digivolt
Market News

Digivolt Introduces Tokenized Access to Clean-Energy Production

by Kelly Cromley
Dec 4, 2025

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.