• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Npm Packages Used in Coordinated GitHub Campaign to Deliver Malware
Share
  • bitcoinBitcoin(BTC)$115,089.00
  • ethereumEthereum(ETH)$4,530.19
  • rippleXRP(XRP)$3.05
  • tetherTether(USDT)$1.00
  • solanaSolana(SOL)$239.14
  • binancecoinBNB(BNB)$906.45
  • usd-coinUSDC(USDC)$1.00
  • dogecoinDogecoin(DOGE)$0.261172
  • staked-etherLido Staked Ether(STETH)$4,525.87
  • tronTRON(TRX)$0.348705
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
Blockchain

Npm Packages Used in Coordinated GitHub Campaign to Deliver Malware

News Desk
Last updated: September 3, 2025 9:42 pm
News Desk
Published: September 3, 2025
Share
4050956 0 93667700 1756933422 shutterstock 712558591 100963102 orig

In a troubling development within the realm of software supply chain security, researchers from ReversingLabs have identified two malicious npm packages, colortoolsv2 and mimelib2, which were discovered in July. These packages exploited Ethereum smart contracts to facilitate malware delivery, highlighting a significant threat to developers and the broader tech community.

Unlike many supply chain attacks that typically aim to disguise rogue packages as legitimate offerings, these particular npm packages did not make an extensive effort to appear appealing to potential users. Instead, they contained only the essential files necessary to execute their malicious functions. This pointed to a broader strategy, as these rogue packages were part of a coordinated campaign aimed at deceiving users into executing code from counterfeit GitHub repositories.

These repositories, which falsely claimed to provide tools for automated cryptocurrency trading bots, were crafted to seem credible. They displayed traits of legitimacy, such as multiple active contributors, thousands of code commits, and an array of stars typically associated with popular repositories. However, the researchers uncovered that these attributes had been artificially inflated using sockpuppet accounts that were created concurrently with the emergence of the npm packages.

Such tactics represent a stark reminder of the vulnerabilities present in software development and package management ecosystems. As the attack’s method of obfuscation demonstrates, malicious actors are continuously evolving their approaches to exploit vulnerabilities and trick unsuspecting developers into downloading harmful software.

Stakeholders within the tech industry are urged to remain vigilant and adopt best practices to verify package legitimacy, including scrutinizing the authenticity of repository contributors and examining the underlying code for any suspicious activity. The incident underscores the critical importance of maintaining robust security measures in software development processes to safeguard against evolving threats.

OpenLedger: Redefining the Future of Finance with AI and Blockchain Integration
CratD2C Launches as a New Competitor in the Layer 1 Blockchain Market with Innovative Features and Token Sale
Cryptocurrency Sector Thrives Amid Policy Shifts and Technological Advancements
Galaxy Digital Becomes First Nasdaq-Listed Company to Tokenize SEC-Registered Shares on Blockchain
Stripe and Paradigm Team Up to Launch Tempo, a New Stablecoin-Focused Blockchain
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article bic altcoins alt coins covers neutral 1 1 Top Altcoins Poised for New All-Time Highs in September: Ethereum, XRP, and Tron
Next Article 1756936272 0x0 DeXRP Innovates Decentralized Finance with Hybrid Model on XRP Ledger
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
large figure logo OG jpg c0809abe4d.webp
Figure Technology Solutions Makes Strong Nasdaq Debut, Co-Founder Aims for Web3 Leadership
8e646fbca65ca3788aca2b9a74b435e8
David Ellison Targets $71 Billion Warner Bros. Discovery After Paramount Takeover
ff3c0dbe20f71f9b977b3900284e2ffe5973e414 1920x1079
Market Sentiment Remains Bullish Post-CPI Report as Traders Anticipate Fed Rate Cuts
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Finance
  • News
  • Company
  • Bitcoin
  • Ethereum
  • XRP
  • Altcoins
  • Blockchain
  • DeFi
  • Stocks
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?