Sunday, November 16, 2025
DIGESTWIRE
Contribute
CONTACT US
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
DIGESTWIRE
No Result
View All Result
Home Blockchain

Ethereum Smart Contracts Misused As Tools For Hiding Malware

by DigestWire member
September 4, 2025
in Blockchain, Crypto Market, Cryptocurrency
0
Ethereum Smart Contracts Misused As Tools For Hiding Malware
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Radiant Capital Hacker Nearly Doubles Stolen Funds Through Ethereum Trading

The post Ethereum Smart Contracts Misused As Tools For Hiding Malware appeared first on Coinpedia Fintech News

Ethereum, the backbone of crypto apps and DeFi projects, is increasingly being used as a tool for cyberattacks.

Researchers at ReversingLabs have found two npm packages that hid malicious commands inside Ethereum smart contracts, marking a new twist in software supply chain attacks.

Read on to know how this was carried out.

Simple Packages With Hidden Malwares

The two packages, colortoolsv2 and mimelib2, looked like harmless tools, but they secretly pulled in downloader malware. These packages are part of a broader, sophisticated campaign spreading across npm and GitHub.

In July, RL discovered colortoolsv2 using blockchain to deliver malware. It was quickly removed, but a near-identical package called mimelib2 soon appeared with the same malicious code. 

Both npm packages were minimal and carried only the malware, while their GitHub repositories were made to look polished and reliable to fool developers.

Using Smart Contracts as a Stealth Tool

What makes this campaign stand out is how the attackers used Ethereum smart contracts to hide malicious URLs.

Colortoolsv2 appeared to be a basic npm package with only two files. Hidden inside was a script that downloaded additional malware from a command-and-control server. Usually, malware campaigns hardcode URLs into their code, which makes them easier to detect. 

In this case, the URLs were stored inside Ethereum smart contracts, making it much harder to track and shut down the attack.

“That’s something we haven’t seen previously, and it highlights the fast evolution of detection evasion strategies by malicious actors who are trolling open source repositories and developers,” the researchers said. 

Hackers Are Getting More Creative 

This attack is part of a growing trend where hackers are finding new ways to deliver malware. In 2023, some Python packages hid malicious URLs inside GitHub Gists, and in 2022, a fake Tailwind CSS npm package stored malware links behind trusted platforms like Google Drive and OneDrive.

eth

How GitHub Was Used as Trap

The attackers also built fake GitHub repositories to make their campaign more convincing.

Attackers set up fake repositories tied to the colortoolsv2 package, posing as crypto trading bots. These projects looked convincing, with thousands of commits, active contributors, and plenty of stars. 

But the activity and popularity were faked to trick developers into downloading poisoned code.

This campaign didn’t stop with solana-trading-bot-v2. Other repos like ethereum-mev-bot-v2, arbitrage-bot, and hyperliquid-trading-bot also showed fake commits and activity, though less convincing.

Last year saw 23 campaigns where attackers planted malicious code in open-source repos, including the ultralytics PyPI crypto miner and an April 2025 malware attempt on local crypto tools. 

For developers, this is a reminder to carefully vet open-source libraries. Stars, downloads, and activity do not guarantee trust. Both code and maintainers need to be thoroughly reviewed before integration.

Read Entire Article
Tags: BlockchainCoin SurgesCoinPedia
Share30Tweet19
Next Post

XRP Ledger Activates On-Chain KYC/AML In Major Upgrade

$375,000 Bitcoin? Market Veteran Says It’s Closer Than You Think

‘Dreams of a Life’ Filmmaker Carol Morley Set to Direct Adaptation of Her Novel ‘7 Miles Out’ (EXCLUSIVE)

‘Dreams of a Life’ Filmmaker Carol Morley Set to Direct Adaptation of Her Novel ‘7 Miles Out’ (EXCLUSIVE)

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

No Result
View All Result
Coins MarketCap Live Updates Coins MarketCap Live Updates Coins MarketCap Live Updates
ADVERTISEMENT

Highlights

Albania v England: Line-ups, stats and preview

Bill Belichick Shuts Down NFL Coaching Rumors: ‘We’re On To Wake Forest’

RHOP’s Karen Huger Gets Standing Ovation at BravoCon After Prison Release

Jeff Lewis Confirms He Apologized to Andy Cohen After BravoCon 2025 Panel

Bows, Collars, Stripes! 19 Boutique-Style Pieces to Look So Parisian — From $6

Dolores Catania Says Fiance Paulie Is ‘Happy to Close’ His Divorce Chapter

Trending

Dan McGrath, Emmy-Winning Writer for ‘The Simpsons,’ Dies at 61
Entertainment

Dan McGrath, Emmy-Winning Writer for ‘The Simpsons,’ Dies at 61

by DigestWire member
November 16, 2025
0

Dan McGrath, an Emmy-winning writer for “The Simpsons” who wrote the classic Season 8 episode “Homer’s Phobia,”...

10 Factors Shaping Bitcoin’s Fate: 5 Reasons It Could Rebound — and 5 That Could Drag It Lower

10 Factors Shaping Bitcoin’s Fate: 5 Reasons It Could Rebound — and 5 That Could Drag It Lower

November 15, 2025
Azerbaijan v France: Line-ups, stats and preview

Azerbaijan v France: Line-ups, stats and preview

November 15, 2025
Albania v England: Line-ups, stats and preview

Albania v England: Line-ups, stats and preview

November 15, 2025
Bill Belichick Shuts Down NFL Coaching Rumors: ‘We’re On To Wake Forest’

Bill Belichick Shuts Down NFL Coaching Rumors: ‘We’re On To Wake Forest’

November 15, 2025
DIGEST WIRE

DigestWire is an automated news feed that utilizes AI technology to gather information from sources with varying perspectives. This allows users to gain a comprehensive understanding of different arguments and make informed decisions. DigestWire is dedicated to serving the public interest and upholding democratic values.

Privacy Policy     Terms and Conditions

Recent News

  • Dan McGrath, Emmy-Winning Writer for ‘The Simpsons,’ Dies at 61 November 16, 2025
  • 10 Factors Shaping Bitcoin’s Fate: 5 Reasons It Could Rebound — and 5 That Could Drag It Lower November 15, 2025
  • Azerbaijan v France: Line-ups, stats and preview November 15, 2025

Categories

  • Blockchain
  • Blog
  • Breaking News
  • Business
  • Cricket
  • Crypto Market
  • Cryptocurrency
  • Defense
  • Entertainment
  • Football
  • Founders
  • Health Care
  • Opinion
  • Politics
  • Sports
  • Strange
  • Technology
  • UK News
  • Uncategorized
  • US News
  • World

© 2020-23 Digest Wire. All rights belong to their respective owners.

No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Blockchain
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Strange
  • Blog
  • Founders
  • Contribute!

© 2024 Digest Wire - All right reserved.

Privacy Policy   Terms and Conditions

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.