By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
bitcoin
Bitcoin (BTC) $ 87,753.00
ethereum
Ethereum (ETH) $ 2,904.75
xrp
XRP (XRP) $ 1.88
tether
Tether (USDT) $ 0.998748
solana
Solana (SOL) $ 123.28
bnb
BNB (BNB) $ 878.71
usd-coin
USDC (USDC) $ 0.999719
dogecoin
Dogecoin (DOGE) $ 0.121804
cardano
Cardano (ADA) $ 0.348783
staked-ether
Lido Staked Ether (STETH) $ 2,905.45
tron
TRON (TRX) $ 0.293368
chainlink
Chainlink (LINK) $ 11.85
avalanche-2
Avalanche (AVAX) $ 11.64
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 87,501.00
wrapped-steth
Wrapped stETH (WSTETH) $ 3,561.40
the-open-network
Toncoin (TON) $ 1.51
stellar
Stellar (XLM) $ 0.205286
hedera-hashgraph
Hedera (HBAR) $ 0.105366
sui
Sui (SUI) $ 1.43
shiba-inu
Shiba Inu (SHIB) $ 0.000008
weth
WETH (WETH) $ 2,906.20
leo-token
LEO Token (LEO) $ 9.24
polkadot
Polkadot (DOT) $ 1.84
litecoin
Litecoin (LTC) $ 68.62
bitget-token
Bitget Token (BGB) $ 3.57
bitcoin-cash
Bitcoin Cash (BCH) $ 587.86
hyperliquid
Hyperliquid (HYPE) $ 27.44
usds
USDS (USDS) $ 0.99968
uniswap
Uniswap (UNI) $ 4.65
cryptoprune cryptoprune
  • MarketCap
  • Crypto Bubbles
  • Multi Currency
  • Evaluation
  • Home
  • News
  • Crypto
    • Altcoins
    • Bitcoin
    • Blockchain
    • Cardano
    • Ethereum
    • NFT
    • Solana
  • Market
  • Mining
  • Exchange
  • Regulation
  • Metaverse
Crypto PruneCrypto Prune
  • Home
  • News
  • Crypto
    • Altcoins
    • Bitcoin
    • Blockchain
    • Cardano
    • Ethereum
    • NFT
    • Solana
  • Market
  • Mining
  • Exchange
  • Regulation
  • Metaverse

Search

  • Home
  • News
  • Crypto
    • Altcoins
    • Bitcoin
    • Blockchain
    • Cardano
    • Ethereum
    • NFT
    • Solana
  • Market
  • Mining
  • Exchange
  • Regulation
  • Metaverse

Latest Stories

Russia declares Ukrainian Bitcoin exchange 'undesirable'
Russia declares Ukrainian Bitcoin exchange ‘undesirable’
image
Wallet Connect launches Pay, emphasizing that payments are the “final frontier” of cryptocurrencies
Weekend theft reveals flaws that threaten the security of the US government's $28 billion Bitcoin reserves
Weekend theft reveals flaws that threaten the security of the US government’s $28 billion Bitcoin reserves
Bitcoin
Bitcoin price enters next parabolic phase, analysts set new targets
image
How to find NFT gifts
© 2025 All Rights reserved | Powered by Crypto Prune
Crypto Prune > News > Crypto > Ethereum > Ethereum Smart Contracts quietly push JavaScript malware targeted at developers
Ethereum

Ethereum Smart Contracts quietly push JavaScript malware targeted at developers

5 months ago 4 Min Read

Hackers use Ethereum Smart Contracts to hide malware payloads within seemingly benign NPM packages. This is a tactic that transforms the blockchain into a resilient command channel and complicates takedowns.

ReverSingLabs detailed two npm packages, colortoolsv2 and Mimelib2it read Ethereum contract to get the URL of the second stage downloader, not the hardcoded infrastructure of the package itself.

The package surfaced in July and was removed after disclosure. ReverSingLabs tracked promotions to a network of GitHub repositories posed as trading bots. Solana-trading-bot-v2with fake stars, bulging commit history, and sock puppet maintainers. This is the social class that directs developers towards malicious dependency chains.

The downloads were low, but the method was important. According to hacker news, colortoolsv2 I saw 7 downloads Mimelib2 One still fits opportunistic developer targeting. Snyk and OSV list both packages as malicious and provide quick checks to teams auditing historic builds.

History repeats itself

The on-chain command channel echoes a wider campaign that researchers tracked in late 2024 with a type skirt of hundreds of npm. In that wave, the package queried the Ethereum contract, got the base URL, then ran an installation or pre-install script that downloaded the named OS-specific payload. node-win.exe, node-linuxor node-macos.

CheckMarx Documented Core Contract 0xa1b40044EBc2794f207D45143Bd82a1B86156c6b Coupled with wallet parameters 0x52221c293a21D8CA7AFD01Ac6bFAC7175D590A84using observed infrastructure 45.125.67.172:1337 and 193.233.201.21:3001especially.

Phylum’s Deobfuscation shows ethers.js I’ll call getString(address) With the same contract, log C2 rotations over time. This is the action of turning contract status into a malware search moving pointer. Socket independently mapped Typosquat floods, exposed matching IOCs containing the same contracts and wallets, and verified cross-source consistency.

See also  Ethereum price drops below $3,000 after 3 days of outflows from ETH ETF

Old vulnerabilities continue to thrive

ReverSingLabs frames the 2025 package as a continuation of technique rather than scale, with the twist of smart contracts hosting URLs at the next stage rather than payload.

GitHub’s delivery work, including fake stargazers and chore commits, aims to pass casual due diligence and take advantage of automated dependency updates within fake repository clones.

Crypto Investor Blueprint: 5-day course on bag holdings, insider frontrunning, and lost alpha

Nice 😎 Your first lesson is approaching.

Please add (Email protection) On your email whitelist.

This design is similar to previous uses of indirect third-party platforms, such as Github Gist and Cloud Storage, but adds immutable storage, public readability, and neutral venues that defenders cannot easily take offline.

For each ReversingLabs, the concrete IOCs in these reports include Ethereum contracts 0x1f117a1b07c108eae05a5bccbe86922d66227e2b Linked to the July package and the 2024 contract 0xa1b40044EBc2794f207D45143Bd82a1B86156c6bwallet 0x52221c293a21D8CA7AFD01Ac6bFAC7175D590A84host pattern 45.125.67.172 and 193.233.201.21 Port 1337 or 3001, and the platform payload name above.

Included in the second stage hash of 2025 021d0eef8f457eb2a9f9fb2260dd2e391f009a21and for 2024 Wave, CheckMarx lists Windows, Linux, and MacOS SHA-256 values. ReverSingLabs has released SHA-1 for each malicious NPM version. This helps teams scan artifact stores for past exposures.

Protect from attacks

For protection, immediate control is to prevent lifecycle scripts from being executed during installation and CI. NPM Documents --ignore-scripts Flag npm ci and npm installand the team can set it globally .npmrcselectively allow the required builds in another step.

The node.js security best practices page advises the same approach, along with pinning versions via a more stringent review of lock files and maintainers and metadata.

See also  The power of Bitcoin compared to nuclear reactors by Brazilian business leaders

Block outbound traffic to the above IOC and warn it in the build log that initializes ethers.js For a query getString(address) It provides practical detection that matches chain-based C2 designs.

The package is gone, the patterns remain, and the on-chain interdirection sits alongside the type skirt and fake repository as a repeatable way to reach the developer machine.

TAGGED:CoinsCryptoEthereum AnalysisEthereum News
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RELATED NEWS

Nvidia's revenues are in the spotlight

Nvidia’s revenues are in the spotlight

By Crypto Prune 8 months ago
Bitcoin

Five Years left: Solana co-founders encourage the Bitcoin community to use quantum threat equipment

By Crypto Prune 4 months ago
ETH recovery builds strength above $2,620, with traders looking at $2,700

ETH recovery builds strength above $2,620, with traders looking at $2,700

By Crypto Prune 8 months ago
Bitcoin price

Bitcoin prices currently at intersections – under $10,000 or the height of a new cycle?

By Crypto Prune 8 months ago
cryptoprune

© 2025 All Rights reserved | Powered by Crypto Prune

  • Altcoins
  • Bitcoin
  • Blockchain
  • Cardano
  • Ethereum
  • Exchange
  • Market
  • Metaverse
  • Mining
  • News
  • Crypto
  • NFT
  • Solana
  • Regulation
  • Technology
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?