Malicious npm packages use Ethereum blockchain for malware delivery

Malicious npm packages use Ethereum blockchain for malware delivery


Npm as obfuscation layer for GitHub campaign

The ReversingLabs researchers discovered two rogue npm packages called colortoolsv2 and mimelib2 that used Ethereum smart contracts for malware delivery in July. But not much effort was put into making those packages look legitimate and attractive for developers to include in their projects, which is usually the goal of supply chain attacks with rogue npm packages.

The colortoolsv2 package — and the mimelib2 one that later replaced it — contained only the files needed to implement the malicious functionality. As the researchers later found, this was because they were part of a larger coordinated campaign, the focus of which was to trick users into running code from fake GitHub repositories that would then download the npm packages automatically as dependencies.

The rogue GitHub repositories claimed to be for automated cryptocurrency trading bots and were crafted to look legitimate. They appeared to have multiple active contributors, thousands of code commits, and multiple stars, but these were all faked with sockpuppet accounts created around the same time as the npm packages popped up.

Jennifer Avatar

🌟 Jennifer – Crypto Enthusiast & Blockchain Explorer 🌟

Hi, I’m Jennifer! 💻✨
I’m passionate about all things crypto, blockchain, and cutting-edge technology. As a dedicated content creator, I love sharing the latest news, trends, and insights from the ever-evolving world of cryptocurrency. From Bitcoin to DeFi, NFTs to smart contracts, I’m always on the lookout for the next big thing in the blockchain space.

🔍 What I Do:


✅ Share breaking crypto news and updates.
✅ Explore blockchain innovations and their real-world applications.
✅ Dive into emerging technologies shaping the future of finance and beyond.
✅ Connect with like-minded crypto enthusiasts and build a strong community.