Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Attackers Exploit Ethereum Smart Contracts in Supply Chain Breach

Attackers Exploit Ethereum Smart Contracts in Supply Chain Breach

Rogue npm packages and fake GitHub repos used to spread malware

Kelly Cromley by Kelly Cromley
Sep 4, 2025
in Ethereum News, Market News, News
Reading Time: 3 mins read
0
Ethereum

A recent cybersecurity incident has revealed how attackers combined blockchain technology with traditional software repositories to execute a supply chain attack. According to research by ReversingLabs, the threat actors involved deployed rogue npm packages and manipulated GitHub repositories, using Ethereum smart contracts to conceal malware payloads. The campaign is believed to have primarily targeted developers and users in the cryptocurrency sector.

A Shift in Attack Techniques

The researchers highlighted that the incident reflected a growing sophistication in repository-based attacks. They noted that attackers were increasingly attempting to implant malicious code into legitimate applications, with the dual objectives of stealing sensitive development assets and exfiltrating digital resources.

The investigation showed that the attackers utilized Ethereum smart contracts to hide URLs containing secondary malware payloads. This tactic likely helped them evade detection from automated security tools that scan npm packages for suspicious links or commands.

Discovery of Rogue npm Packages

In July, ReversingLabs identified two malicious npm packages named colortoolsv2 and mimelib2. These were found to leverage Ethereum smart contracts for delivering malware. Interestingly, the packages did not make significant efforts to appear legitimate or attractive to developers, which is the usual approach in supply chain compromises. Instead, the researchers concluded that these packages were only one part of a broader coordinated scheme.

Both colortoolsv2 and mimelib2 contained only the files required to perform their malicious tasks. Their primary role was to act as dependencies for fake GitHub repositories that unsuspecting users were tricked into running. Once executed, these repositories would automatically download the rogue npm packages.

Fake GitHub Repositories Crafted to Deceive

The malicious GitHub projects were disguised as automated cryptocurrency trading bots. They appeared convincing by showcasing thousands of code commits, multiple stars, and numerous active contributors. However, deeper analysis revealed that the activity was fabricated.

The accounts behind the commits were sockpuppets, all created around the same period as the npm packages. The inflated activity gave the false impression of legitimacy. ReversingLabs discovered that most commits involved repetitive modifications to the project’s LICENSE file, while genuine changes were limited to code that executed and downloaded the rogue npm dependencies.

⚠️ New RL threat research: 2 malicious #npm packages abuse #Ethereum smart contracts to load #malware on compromised devices. https://t.co/wzDRKfm2yh

— ReversingLabs (@ReversingLabs) September 3, 2025


The researchers observed that the infrastructure used for these commits appeared automated, with thousands being added daily, signaling a well-orchestrated attempt to maintain the illusion of an active development community.

Use of Ethereum for Malware Delivery

The malicious npm packages included code that connected to the Ethereum blockchain. While such a feature might not immediately appear suspicious in a cryptocurrency-related library, its actual purpose was to retrieve hidden URLs stored in Ethereum smart contracts. These URLs then facilitated the download of malware payloads. Smart contracts, which are small programs executed automatically on the blockchain, were thus repurposed as a tool to distribute malicious links covertly.

Lessons for Developers

The campaign underscored the importance of rigorous due diligence when integrating open-source software into projects. Researchers stressed that developers should evaluate not just the raw statistics of a package—such as contributor counts, number of commits, or download volumes—but also verify the authenticity of maintainers and their contributions.

This case has been seen as a warning to the broader development community that supply chain threats are evolving rapidly. With attackers blending blockchain tools and repository manipulation, developers are urged to adopt a deeper level of scrutiny before incorporating third-party libraries into their workflows.

Previous Post

Ondo Finance Opens Tokenized Access to U.S. Stocks

Next Post

Trimont Taps JPMorgan’s Kinexys for Faster Real Estate Payments

Related Posts

U.S. Securities and Exchange Commission (SEC)

US SEC Moves to Remove Key Barrier for Tokenized Stock Trading

by Kelly Cromley
Jun 13, 2026
0

The US Securities and Exchange Commission (SEC) has introduced a regulatory proposal that could significantly reshape the framework governing stock...

TRON

Pizza Hut Paraguay Expands Crypto Payments With USDT on TRON

by Kelly Cromley
Jun 13, 2026
0

TRON DAO has drawn attention to the expanding real-world use of cryptocurrency payments by showcasing a Pizza Hut location in...

mantle

Mantle Launches AI-Powered InsightX Ahead of 2026 World Cup

by Kelly Cromley
Jun 13, 2026
0

As the 2026 FIFA World Cup approaches, competition among crypto-native betting and prediction platforms is intensifying. Blockchain network Mantle has...

tradingrazor

TradingRazor and ENI Join Forces to Advance AI-Powered Web3

by Kelly Cromley
Jun 13, 2026
0

TradingRazor, a prominent cryptocurrency analytics and trading platform, has announced a strategic partnership with ENI, a modular Layer-1 blockchain network....

chainspect

Fastest Blockchains Revealed as Chainspect Compares Block Times

by Kelly Cromley
Jun 12, 2026
0

New data published by blockchain analytics platform Chainspect has shed light on the significant differences in block production speeds across...

Atua AI

Atua AI Expands Automation Capabilities for Decentralized Enterprises

by Kelly Cromley
Jun 12, 2026
0

Atua AI, a decentralized artificial intelligence platform specializing in productivity and automation solutions, has unveiled a new set of AI-powered...

Next Post
trimont

Trimont Taps JPMorgan’s Kinexys for Faster Real Estate Payments

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

U.S. Securities and Exchange Commission (SEC)
Market News

US SEC Moves to Remove Key Barrier for Tokenized Stock Trading

by Kelly Cromley
Jun 13, 2026
TRON
Market News

Pizza Hut Paraguay Expands Crypto Payments With USDT on TRON

by Kelly Cromley
Jun 13, 2026
mantle
Market News

Mantle Launches AI-Powered InsightX Ahead of 2026 World Cup

by Kelly Cromley
Jun 13, 2026
tradingrazor
Market News

TradingRazor and ENI Join Forces to Advance AI-Powered Web3

by Kelly Cromley
Jun 13, 2026
chainspect
Market News

Fastest Blockchains Revealed as Chainspect Compares Block Times

by Kelly Cromley
Jun 12, 2026

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.