• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Hackers Exploit NPM Vulnerabilities to Inject Malware into Ethereum Smart Contracts
Share
  • bitcoinBitcoin(BTC)$71,242.00
  • ethereumEthereum(ETH)$2,104.80
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$693.50
  • rippleXRP(XRP)$1.45
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$90.74
  • tronTRON(TRX)$0.281157
  • staked-etherLido Staked Ether(STETH)$2,260.93
  • dogecoinDogecoin(DOGE)$0.102791
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
Ethereum

Hackers Exploit NPM Vulnerabilities to Inject Malware into Ethereum Smart Contracts

News Desk
Last updated: September 4, 2025 2:31 pm
News Desk
Published: September 4, 2025
Share
1756989479 stock image optimized 2025 09 04t133749 763

Hackers are increasingly targeting vulnerabilities in widely-used Node Package Manager (NPM) coding libraries to inject malware into Ethereum smart contracts, according to recent research by cryptocurrency compliance firm Reversing Labs. In a blog post on September 3, researcher Lucija Valentić highlighted the discovery of new forms of malware, notably the packages “colortoolsv2” and “mimelib2.” These packages, released in July 2025, exploit smart contracts, embedding harmful commands designed to install downloader malware on compromised systems.

The attack vectors are part of a growing trend where malicious supply chain actors leverage sophisticated social engineering techniques to persuade developers into incorporating harmful code into their projects. Reversing Labs noted that 2025 has seen a diverse array of campaigns targeting NPM, the primary online repository for JavaScript packages. For instance, in March, they documented the emergence of packages labeled ethers-provider2 and ethers-providerz, which are part of a larger cluster of infostealers and other malicious tools identified on NPM.

In July, researcher Karlo Zanki uncovered a campaign utilizing a basic package designed to deploy blockchain functionality in a novel way, facilitating the malicious second stage. One significant finding was the colortoolsv2 package, identified as an infiltrator of Ethereum smart contracts. This seemingly simple NPM package actually conceals a hidden malicious payload within a script named index.js. Upon installation, this script fetches blockchain data and executes harmful commands by connecting to a command and control (C2) server, ultimately downloading additional malicious software.

What makes this method particularly concerning is the unusual use of Ethereum smart contracts to host the actual URLs for downloading this second-stage malware. Researchers have pointed out that they haven’t encountered such a tactic previously.

In a striking example, the researchers discovered a version of a Solana trading bot infected by the colortoolsv2 package, which appeared legitimate on the surface. This repository showcased thousands of commits, numerous contributors, and a significant volume of user engagement—all characteristics that would typically signal a trustworthy open-source project. However, the details were fabricated, and any developer installing this bot risked having their user wallets drained.

The rise of software supply chain attacks on smart contracts and blockchain infrastructure has been alarming. In July, a vulnerability in Arcadia Finance’s Rebalancer contract allowed hackers to drain approximately $2.5 million in cryptocurrency from the platform operating on the Base blockchain. By manipulating arbitrary parameters for swaps, the attackers executed unauthorized transactions that emptied user vaults.

Blockchain analytics firm Global Ledger revealed a staggering statistic: hackers have stolen an estimated $3 billion worth of cryptocurrency across 119 separate incidents in the first half of 2025 alone, marking a 150% increase over the total thefts recorded in all of 2024. Slava Demchuk, CEO of analytics firm AMLBot, emphasized that access-control flaws and vulnerabilities in smart contracts, particularly in bridges, have become frequent targets for exploitation.

As the situation intensifies, blockchain auditors recommend that developers rigorously assess each library before integrating it into their projects to mitigate potential threats effectively. This heightened scrutiny is essential in the evolving landscape of decentralized finance (DeFi), where interconnected protocols amplify the risk of security breaches.

Bitcoin Drops Below $110K Amid Market Panic and Rate Cut Uncertainty
BlackRock’s Ethereum ETF Sees $363 Million Inflows, Marking a Turnaround for Ethereum
U.S. Spot Ethereum ETFs Experience Major Outflows as Institutional Demand Fluctuates
Ethereum’s Complex Narrative Gains Momentum as Institutions Begin to Embrace DeFi
Ethereum and Dogecoin Experience Price Pullbacks Amid Rising Interest in Digitap’s $TAP Presale
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article K3HTLVBRAJEIZCWCCG4K45BY7M BNB Chain Celebrates Five Years of Growth with Record User Engagement and Innovative Upgrades
Next Article brian armstrong coinbase decrypt style 2 gID 7 Coinbase CEO Aims for 50% of Code to be AI-Generated by October
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
6979fc73116a3.image
OKX Launches Cryptocurrency Payment Card in Europe
a239e460 01fe 11f1 973f 5fc1f3abbce6
Bitcoin Falls Below $73,000 as Treasury Secretary Rules Out Government Bailout
20220509000002743000e261de8
Gold Stocks Continue Downward Trend Amid Market Volatility
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Finance
  • News
  • Company
  • Stocks
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?