Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Attackers Exploit Ethereum Smart Contracts in Supply Chain Breach

Attackers Exploit Ethereum Smart Contracts in Supply Chain Breach

Rogue npm packages and fake GitHub repos used to spread malware

Kelly Cromley by Kelly Cromley
Sep 4, 2025
in Ethereum News, Market News, News
Reading Time: 3 mins read
0
Ethereum

A recent cybersecurity incident has revealed how attackers combined blockchain technology with traditional software repositories to execute a supply chain attack. According to research by ReversingLabs, the threat actors involved deployed rogue npm packages and manipulated GitHub repositories, using Ethereum smart contracts to conceal malware payloads. The campaign is believed to have primarily targeted developers and users in the cryptocurrency sector.

A Shift in Attack Techniques

The researchers highlighted that the incident reflected a growing sophistication in repository-based attacks. They noted that attackers were increasingly attempting to implant malicious code into legitimate applications, with the dual objectives of stealing sensitive development assets and exfiltrating digital resources.

The investigation showed that the attackers utilized Ethereum smart contracts to hide URLs containing secondary malware payloads. This tactic likely helped them evade detection from automated security tools that scan npm packages for suspicious links or commands.

Discovery of Rogue npm Packages

In July, ReversingLabs identified two malicious npm packages named colortoolsv2 and mimelib2. These were found to leverage Ethereum smart contracts for delivering malware. Interestingly, the packages did not make significant efforts to appear legitimate or attractive to developers, which is the usual approach in supply chain compromises. Instead, the researchers concluded that these packages were only one part of a broader coordinated scheme.

Both colortoolsv2 and mimelib2 contained only the files required to perform their malicious tasks. Their primary role was to act as dependencies for fake GitHub repositories that unsuspecting users were tricked into running. Once executed, these repositories would automatically download the rogue npm packages.

Fake GitHub Repositories Crafted to Deceive

The malicious GitHub projects were disguised as automated cryptocurrency trading bots. They appeared convincing by showcasing thousands of code commits, multiple stars, and numerous active contributors. However, deeper analysis revealed that the activity was fabricated.

The accounts behind the commits were sockpuppets, all created around the same period as the npm packages. The inflated activity gave the false impression of legitimacy. ReversingLabs discovered that most commits involved repetitive modifications to the project’s LICENSE file, while genuine changes were limited to code that executed and downloaded the rogue npm dependencies.

⚠️ New RL threat research: 2 malicious #npm packages abuse #Ethereum smart contracts to load #malware on compromised devices. https://t.co/wzDRKfm2yh

— ReversingLabs (@ReversingLabs) September 3, 2025


The researchers observed that the infrastructure used for these commits appeared automated, with thousands being added daily, signaling a well-orchestrated attempt to maintain the illusion of an active development community.

Use of Ethereum for Malware Delivery

The malicious npm packages included code that connected to the Ethereum blockchain. While such a feature might not immediately appear suspicious in a cryptocurrency-related library, its actual purpose was to retrieve hidden URLs stored in Ethereum smart contracts. These URLs then facilitated the download of malware payloads. Smart contracts, which are small programs executed automatically on the blockchain, were thus repurposed as a tool to distribute malicious links covertly.

Lessons for Developers

The campaign underscored the importance of rigorous due diligence when integrating open-source software into projects. Researchers stressed that developers should evaluate not just the raw statistics of a package—such as contributor counts, number of commits, or download volumes—but also verify the authenticity of maintainers and their contributions.

This case has been seen as a warning to the broader development community that supply chain threats are evolving rapidly. With attackers blending blockchain tools and repository manipulation, developers are urged to adopt a deeper level of scrutiny before incorporating third-party libraries into their workflows.

Previous Post

Ondo Finance Opens Tokenized Access to U.S. Stocks

Next Post

Trimont Taps JPMorgan’s Kinexys for Faster Real Estate Payments

Related Posts

ripple decentralized ledger

AMINA Bank Integrates Ripple to Modernize Cross-Border Payments

by Kelly Cromley
Dec 13, 2025
0

AMINA Bank, a Switzerland-based financial institution regulated by FINMA, has implemented Ripple Payments to improve how transactions flow between blockchain...

chainlink

MapleStory Universe Adopts Chainlink for Cross-Chain Gaming

by Kelly Cromley
Dec 13, 2025
0

MapleStory Universe, a blockchain-based gaming platform that enables players to create and monetize their own interactive experiences, has revealed its...

chainbase

Chainbase and OpenLedger Join Forces to Advance AI-Driven Web3

by Kelly Cromley
Dec 13, 2025
0

Chainbase, widely recognized for its omnichain data ecosystem designed for artificial intelligence, has announced a strategic collaboration with OpenLedger, a...

deepsafe partners with arc

DeepSafe, ARC Matrix Launch Privacy-First Web3 Security Framework

by Kelly Cromley
Dec 12, 2025
0

DeepSafe, a decentralized cryptographic verification layer designed for Web3 and artificial intelligence ecosystems, has announced a formal alignment with ARC...

Italy

Italy Debuts First Public-Chain Tokenized Minibond

by Kelly Cromley
Dec 12, 2025
0

Italy has taken a decisive step toward modernizing its capital markets with the launch of the country’s first minibond fully...

U.S. Securities and Exchange Commission (SEC)

SEC Approves DTCC Pilot to Tokenize U.S. Securities on Blockchains

by Kelly Cromley
Dec 12, 2025
0

The U.S. Securities and Exchange Commission has authorized a three-year pilot program allowing the clearinghouse responsible for nearly all equity...

Next Post
trimont

Trimont Taps JPMorgan’s Kinexys for Faster Real Estate Payments

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

ripple decentralized ledger
Market News

AMINA Bank Integrates Ripple to Modernize Cross-Border Payments

by Kelly Cromley
Dec 13, 2025
chainlink
Market News

MapleStory Universe Adopts Chainlink for Cross-Chain Gaming

by Kelly Cromley
Dec 13, 2025
chainbase
Market News

Chainbase and OpenLedger Join Forces to Advance AI-Driven Web3

by Kelly Cromley
Dec 13, 2025
deepsafe partners with arc
Market News

DeepSafe, ARC Matrix Launch Privacy-First Web3 Security Framework

by Kelly Cromley
Dec 12, 2025
Italy
Market News

Italy Debuts First Public-Chain Tokenized Minibond

by Kelly Cromley
Dec 12, 2025

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.