Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Attackers Exploit Ethereum Smart Contracts in Supply Chain Breach

Attackers Exploit Ethereum Smart Contracts in Supply Chain Breach

Rogue npm packages and fake GitHub repos used to spread malware

Kelly Cromley by Kelly Cromley
Sep 4, 2025
in Ethereum News, Market News, News
Reading Time: 3 mins read
0
Ethereum

A recent cybersecurity incident has revealed how attackers combined blockchain technology with traditional software repositories to execute a supply chain attack. According to research by ReversingLabs, the threat actors involved deployed rogue npm packages and manipulated GitHub repositories, using Ethereum smart contracts to conceal malware payloads. The campaign is believed to have primarily targeted developers and users in the cryptocurrency sector.

A Shift in Attack Techniques

The researchers highlighted that the incident reflected a growing sophistication in repository-based attacks. They noted that attackers were increasingly attempting to implant malicious code into legitimate applications, with the dual objectives of stealing sensitive development assets and exfiltrating digital resources.

The investigation showed that the attackers utilized Ethereum smart contracts to hide URLs containing secondary malware payloads. This tactic likely helped them evade detection from automated security tools that scan npm packages for suspicious links or commands.

Discovery of Rogue npm Packages

In July, ReversingLabs identified two malicious npm packages named colortoolsv2 and mimelib2. These were found to leverage Ethereum smart contracts for delivering malware. Interestingly, the packages did not make significant efforts to appear legitimate or attractive to developers, which is the usual approach in supply chain compromises. Instead, the researchers concluded that these packages were only one part of a broader coordinated scheme.

Both colortoolsv2 and mimelib2 contained only the files required to perform their malicious tasks. Their primary role was to act as dependencies for fake GitHub repositories that unsuspecting users were tricked into running. Once executed, these repositories would automatically download the rogue npm packages.

Fake GitHub Repositories Crafted to Deceive

The malicious GitHub projects were disguised as automated cryptocurrency trading bots. They appeared convincing by showcasing thousands of code commits, multiple stars, and numerous active contributors. However, deeper analysis revealed that the activity was fabricated.

The accounts behind the commits were sockpuppets, all created around the same period as the npm packages. The inflated activity gave the false impression of legitimacy. ReversingLabs discovered that most commits involved repetitive modifications to the project’s LICENSE file, while genuine changes were limited to code that executed and downloaded the rogue npm dependencies.

⚠️ New RL threat research: 2 malicious #npm packages abuse #Ethereum smart contracts to load #malware on compromised devices. https://t.co/wzDRKfm2yh

— ReversingLabs (@ReversingLabs) September 3, 2025


The researchers observed that the infrastructure used for these commits appeared automated, with thousands being added daily, signaling a well-orchestrated attempt to maintain the illusion of an active development community.

Use of Ethereum for Malware Delivery

The malicious npm packages included code that connected to the Ethereum blockchain. While such a feature might not immediately appear suspicious in a cryptocurrency-related library, its actual purpose was to retrieve hidden URLs stored in Ethereum smart contracts. These URLs then facilitated the download of malware payloads. Smart contracts, which are small programs executed automatically on the blockchain, were thus repurposed as a tool to distribute malicious links covertly.

Lessons for Developers

The campaign underscored the importance of rigorous due diligence when integrating open-source software into projects. Researchers stressed that developers should evaluate not just the raw statistics of a package—such as contributor counts, number of commits, or download volumes—but also verify the authenticity of maintainers and their contributions.

This case has been seen as a warning to the broader development community that supply chain threats are evolving rapidly. With attackers blending blockchain tools and repository manipulation, developers are urged to adopt a deeper level of scrutiny before incorporating third-party libraries into their workflows.

Previous Post

Ondo Finance Opens Tokenized Access to U.S. Stocks

Next Post

Trimont Taps JPMorgan’s Kinexys for Faster Real Estate Payments

Related Posts

golem

Golem and Salad Test Hybrid Cloud With Decentralized Compute

by Kelly Cromley
Jan 13, 2026
0

Golem Network and Salad.com have entered into a collaboration to examine how a conventional cloud computing platform performs when paired...

votari

Votari Tests Blockchain Voting Through Secure Online Polls

by Kelly Cromley
Jan 13, 2026
0

Votari has begun trialing online voting supported by blockchain technology, signaling a step toward more transparent and verifiable digital elections....

fomoin

Fomoin and MWX Partner to Expand AI Access for Web3 Startups

by Kelly Cromley
Jan 13, 2026
0

Fomoin, a crypto launchpad platform focused on supporting early-stage crypto ventures and Web3 initiatives, has announced a strategic collaboration with...

datavault partners with wellgistics

Wellgistics Advances Blockchain and AI in Pharmacy Systems

by Kelly Cromley
Jan 13, 2026
0

Wellgistics Health, Inc., a health information technology company listed on Nasdaq under the symbol WGRX, has shared an update on...

seedless wallet integrates trustnft security

Remergify Adds TrustNFT Security to Seedless Crypto Wallet

by Kelly Cromley
Jan 13, 2026
0

Remergify, Inc., a company focused on blockchain innovation and corporate asset revitalization, has announced that its Seedless Wallet platform will...

checkmate ecosystem

Checkmate Ecosystem and Team Secret Expand Web3 Gaming

by Kelly Cromley
Jan 13, 2026
0

Checkmate Ecosystem, a community-owned Web3 gaming platform known for titles such as Anichess, has announced a strategic partnership with Team...

Next Post
trimont

Trimont Taps JPMorgan’s Kinexys for Faster Real Estate Payments

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

golem
Market News

Golem and Salad Test Hybrid Cloud With Decentralized Compute

by Kelly Cromley
Jan 13, 2026
votari
Market News

Votari Tests Blockchain Voting Through Secure Online Polls

by Kelly Cromley
Jan 13, 2026
fomoin
Market News

Fomoin and MWX Partner to Expand AI Access for Web3 Startups

by Kelly Cromley
Jan 13, 2026
datavault partners with wellgistics
Market News

Wellgistics Advances Blockchain and AI in Pharmacy Systems

by Kelly Cromley
Jan 13, 2026
seedless wallet integrates trustnft security
Market News

Remergify Adds TrustNFT Security to Seedless Crypto Wallet

by Kelly Cromley
Jan 13, 2026

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.