Threat actors have found a new way to provide malicious software, commands, and links within Ethereum Smart Contracts to avoid security scans as attacks using code repositories evolve.
Cybersecurity researchers at digital asset compliance company ReversingLab have discovered a new piece of new open source malware discovered in the Node Package Manager (NPM) package repository, a large collection of JavaScript packages and libraries.
The malware package employs novel and creative techniques for loading malware into compromised devices – smart contracts for Ethereum Blockchains” said in a blog post Wednesday.
Two packages, Colortoolsv2 and Mimelib2, released in July, “abused smart contracts to hide malicious commands that installed downloader malware on compromised systems,” explained Valentić.
To avoid security scans, the package acted as a simple downloader, and instead of hosting malicious links directly, it obtained command and control server addresses from the smart contract.
Once installed, the package will query the blockchain and fetch the URL to download the second stage malware with payload or action, making detection more difficult as blockchain traffic appears to be legal.

GitHub’s NPM packages “Colortoolsv2” and “Mimelib2”. sauce: ReversingLabs
New attack vector
Malware targeting Ethereum smart contracts is nothing new. It was used earlier this year by the North Korea-related hacking collective The Lazarus Group.
“What’s new and different is to download the second stage malware using Ethereum smart contracts to host the URL where the malicious commands are located,” Valentić said.
“It’s something we’ve never seen before, highlighting the rapid evolution of detection evasion strategies by malicious actors trolling open source repositories and developers.”
Elaborate Crypto-Case Campaign
Malware packages were part of a larger, elaborate social engineering and deception campaign run primarily through GitHub.
The threat actor has created a fake cryptocurrency trading bot repository. The BOT repository is designed to be highly reliable through manufactured commits, fake user accounts created to view the repository, multiple maintainer accounts to simulate active development, and fake user accounts created through professional project descriptions and documentation.
Related: Crypto users warned when ads push Crypto apps containing malware
Threat actors are evolving
In 2024, security researchers documented 23 crypto-related malicious campaigns on open source repositories, but the latest attack vector “indicating the evolution of attacks on repositories.
These attacks don’t just take place in Ethereum. In April, they distributed obscure malware that steals crypto wallet credentials using a fake Github repository disguised as a Solana trading bot. Hackers are also targeting “Bitcoinlib,” an open source Python library designed to facilitate the development of Bitcoin.
magazine: Bitcoin to see “another big thrust” at $150K builds the pressure of ETH: Corporate Secrets
Discover more from Earlybirds Invest
Subscribe to get the latest posts sent to your email.


