• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Cybersecurity Researchers Uncover Malware using Ethereum Smart Contracts on npm Registry
Share
  • bitcoinBitcoin(BTC)$70,654.00
  • ethereumEthereum(ETH)$2,143.54
  • tetherTether(USDT)$1.00
  • rippleXRP(XRP)$1.42
  • binancecoinBNB(BNB)$636.30
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$90.88
  • tronTRON(TRX)$0.308735
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03
  • dogecoinDogecoin(DOGE)$0.093501
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
Ethereum

Cybersecurity Researchers Uncover Malware using Ethereum Smart Contracts on npm Registry

News Desk
Last updated: September 3, 2025 8:59 pm
News Desk
Published: September 3, 2025
Share
eth npm

Cybersecurity researchers have recently uncovered two malicious packages on the npm registry that leverage smart contracts on the Ethereum blockchain to perform harmful actions on compromised systems. This discovery highlights an alarming trend in which threat actors continually seek innovative methods to distribute malware while avoiding detection.

According to ReversingLabs researcher Lucija Valentić, the malicious packages were designed to hide harmful commands that install downloader malware on affected systems. Both packages were uploaded to the npm registry in July 2025 and have since been removed.

ReversingLabs described these packages as being part of a more extensive and organized campaign that impacts both npm and GitHub, targeting unsuspecting developers who inadvertently download and execute them. While the packages themselves do not attempt to disguise their malicious nature, the associated GitHub projects have been crafted to appear genuine and credible.

The worrisome behavior emerges once these packages are utilized or included in other projects, leading to the initiation of a next-stage payload from an attacker-controlled server. What sets these packages apart from traditional malware downloaders is their innovative use of Ethereum smart contracts to stage the URLs from which the payloads are hosted, a method reminiscent of the EtherHiding technique. This strategic shift reflects the evolving tactics used by cybercriminals to evade detection.

Further investigation revealed that the malicious packages are linked to a network of GitHub repositories that falsely claim to be a solana-trading-bot-v2, which purports to use “real-time on-chain data to execute trades automatically.” However, the GitHub account associated with this repository has since been taken down.

Experts believe that these accounts are part of a distribution-as-a-service (DaaS) scheme known as Stargazers Ghost Network. This refers to a cluster of fake GitHub accounts that are designed to enhance the appearances of malicious repositories through various tactics such as starring, forking, and subscribing.

Among the many repositories involved in disseminating the npm packages are those related to cryptocurrency trading, including ethereum-mev-bot-v2, arbitrage-bot, and hyperliquid-trading-bot. The naming conventions of these GitHub repositories indicate that the primary targets of this campaign are developers and users within the cryptocurrency space, relying on a combination of social engineering and deception.

Valentić emphasized the need for developers to vigilantly evaluate libraries before integrating them into their projects. This involves not only examining the packages themselves but also looking into the reputations and histories of their maintainers. The focus should extend beyond superficial metrics such as the number of downloads or commits to determine whether a package and its developers authentically represent what they claim.

Shipyard to Cease Support for libp2p Implementations, Community Transition Planned
Trust Wallet Integrates Tokenized Stocks and ETFs to Enhance Self-Custody Crypto Experience
Solana Apps Outperform Ethereum with $207 Million in Revenue
Ethereum Recovers to $4,037 Despite Recent Declines and Liquidations
Ethereum Undervalued as NVT Ratio Hits Record Low
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article Founder pic 202508 e1756502066436 Kite Raises $18 Million to Build Blockchain Infrastructure for AI Applications
Next Article XRP neutral object 1 Large XRP Faces Challenges at 100-Day EMA Amid Bearish Market Sentiment
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
1774314524 og
Polymarket Traders Gauge Bitcoin Momentum in Real-Time Betting
19f1aade05e238c8e0acbebb36c11396
Contradictory Claims Emergence Amid Market Volatility and Major Crypto Trades
108259745 1769798978051 gettyimages 2241257460 1006 48 fl250913033
Dow Surges Over 600 Points as Experts Weigh in on Commodities and Upcoming Reports
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Company
  • Finance
  • News
  • Stocks
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?