• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Threat Actors Use Ethereum Smart Contracts to Deliver Malware in Evolving Attack Strategy
Share
  • bitcoinBitcoin(BTC)$71,471.00
  • ethereumEthereum(ETH)$2,115.03
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$696.08
  • rippleXRP(XRP)$1.45
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$90.88
  • tronTRON(TRX)$0.281360
  • staked-etherLido Staked Ether(STETH)$2,260.93
  • dogecoinDogecoin(DOGE)$0.102928
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
Ethereum

Threat Actors Use Ethereum Smart Contracts to Deliver Malware in Evolving Attack Strategy

News Desk
Last updated: September 4, 2025 5:07 am
News Desk
Published: September 4, 2025
Share
01991283 4d0c 73ac 8323 3c96bbb3b4e3

Recent research from ReversingLabs has unveiled a sophisticated method employed by threat actors to deliver malware using Ethereum smart contracts. This innovative approach aims to bypass security scans and highlights an alarming evolution in cyber attack strategies targeting code repositories.

According to ReversingLabs, two malicious packages found on the Node Package Manager (NPM), designated as “colortoolsv2” and “mimelib2,” have been utilizing smart contracts on the Ethereum blockchain to conceal malevolent commands. Released in July, these packages function as downloaders that initially appear harmless. Instead of hosting malicious links directly, they cleverly retrieve command and control server addresses from smart contracts when installed on compromised systems.

Lucija Valentić, a ReversingLabs researcher, noted in a recent blog post that when these packages are operational, they query the blockchain to obtain URLs leading to the download of secondary malware. This technique complicates detection efforts because the blockchain transactions appear legitimate, complicating efforts to identify and nullify threats.

While malware targeting Ethereum smart contracts isn’t entirely new—earlier this year, the Lazarus Group, linked to North Korean hacking activities, employed similar tactics—the strategic use of smart contracts to host URLs for downloading malware marks a notable shift. Valentić emphasized that this novel approach underscores the rapid evolution of evasion tactics utilized by malicious actors, particularly in the context of open-source repositories.

The research reveals that these malware packages are part of a broader deception campaign primarily orchestrated through GitHub. Cybercriminals have developed fake cryptocurrency trading bot repositories designed to instill confidence among potential victims. This intricate operation involves fabricated commits, the creation of misleading user accounts to monitor repositories, multiple maintainer accounts designed to project active development, and professional-quality project documentation.

The investigation into these threats comes amid an increasing number of malicious campaigns targeting cryptocurrency users. In 2024 alone, researchers have identified 23 crypto-related malicious efforts linked to open-source repositories. The latest developments reveal the ability of attackers to blend blockchain technology with intricate social engineering, enhancing their chances of evading traditional detection methods.

This evolving threat landscape extends beyond Ethereum. For example, earlier in April, a deceptive repository masquerading as a Solana trading bot was discovered to distribute malware capable of stealing credentials from crypto wallets. Additionally, attacks have also been reported targeting “Bitcoinlib,” an open-source Python library aimed at simplifying Bitcoin development.

As cyber threats continue to advance and exploit newfound vulnerabilities, experts urge users to remain vigilant and adopt robust cybersecurity practices when engaging with open-source repositories and cryptocurrency technologies.

Etherealize Raises $40 Million to Bring Ethereum to Wall Street
Sharplink shares drop 11% amid doubts over ETH acquisition plans
Ethereum Price Faces Fresh Decline, Testing Support Levels
MetaMask poised for token launch, but regulatory risks and speculation persist
Ethereum Price Surges as Bitmine and SharpLink Expand Holdings
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article Blockchain Illustration DICT Secretary Aguda Supports Senator Aquino’s Blockchain Bill for Enhanced Budget Transparency
Next Article 01957079 b2a5 716c 8d1f fba6f23044bf Bitcoin Adoption on the Rise as Businesses Reinvest Profits
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
6979fc73116a3.image
OKX Launches Cryptocurrency Payment Card in Europe
a239e460 01fe 11f1 973f 5fc1f3abbce6
Bitcoin Falls Below $73,000 as Treasury Secretary Rules Out Government Bailout
20220509000002743000e261de8
Gold Stocks Continue Downward Trend Amid Market Volatility
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Finance
  • News
  • Company
  • Stocks
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?