• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Npm Packages Used in Coordinated GitHub Campaign to Deliver Malware
Share
  • bitcoinBitcoin(BTC)$66,838.00
  • ethereumEthereum(ETH)$1,831.42
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$623.39
  • rippleXRP(XRP)$1.29
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$75.60
  • tronTRON(TRX)$0.319722
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03
  • HyperliquidHyperliquid(HYPE)$68.03
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
Blockchain

Npm Packages Used in Coordinated GitHub Campaign to Deliver Malware

News Desk
Last updated: September 3, 2025 9:42 pm
News Desk
Published: September 3, 2025
Share
4050956 0 93667700 1756933422 shutterstock 712558591 100963102 orig

In a troubling development within the realm of software supply chain security, researchers from ReversingLabs have identified two malicious npm packages, colortoolsv2 and mimelib2, which were discovered in July. These packages exploited Ethereum smart contracts to facilitate malware delivery, highlighting a significant threat to developers and the broader tech community.

Unlike many supply chain attacks that typically aim to disguise rogue packages as legitimate offerings, these particular npm packages did not make an extensive effort to appear appealing to potential users. Instead, they contained only the essential files necessary to execute their malicious functions. This pointed to a broader strategy, as these rogue packages were part of a coordinated campaign aimed at deceiving users into executing code from counterfeit GitHub repositories.

These repositories, which falsely claimed to provide tools for automated cryptocurrency trading bots, were crafted to seem credible. They displayed traits of legitimacy, such as multiple active contributors, thousands of code commits, and an array of stars typically associated with popular repositories. However, the researchers uncovered that these attributes had been artificially inflated using sockpuppet accounts that were created concurrently with the emergence of the npm packages.

Such tactics represent a stark reminder of the vulnerabilities present in software development and package management ecosystems. As the attack’s method of obfuscation demonstrates, malicious actors are continuously evolving their approaches to exploit vulnerabilities and trick unsuspecting developers into downloading harmful software.

Stakeholders within the tech industry are urged to remain vigilant and adopt best practices to verify package legitimacy, including scrutinizing the authenticity of repository contributors and examining the underlying code for any suspicious activity. The incident underscores the critical importance of maintaining robust security measures in software development processes to safeguard against evolving threats.

Nasdaq Proposes Trading Tokenized Stocks on Exchange, Pending SEC Approval
OpenLedger: Redefining the Future of Finance with AI and Blockchain Integration
The Future of Cryptocurrency: Bridging Regulatory Gaps with Evolving Technology
Dash to Present at Boston Blockchain Week on September 10th
Rise of Blockchain Technology: Transforming Financial Services and Data Management
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article bic altcoins alt coins covers neutral 1 1 Top Altcoins Poised for New All-Time Highs in September: Ethereum, XRP, and Tron
Next Article 1756936272 0x0 DeXRP Innovates Decentralized Finance with Hybrid Model on XRP Ledger
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
https2F2Fmedia.zenfs .com2Fen2Fmotleyfool.com2F0b531267072989758bedf081cf4f168d
Bitcoin Dips Below $60,000 as Market Panic Grows
urlhttps3A2F2Fg.foolcdn.com2Feditorial2Fimages2F8739702Fdigital money cube placed on a bloc
Coalition of Crypto Firms Urges Senate to Pass Digital Asset Market Clarity Act, Potentially Boosting Solana’s Value
aud usd 02 Medium
AUD/USD Rebounds Near 0.7080 Amid Improved Risk Sentiment Following US-Iran Peace Agreement
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Company
  • Finance
  • Stocks
  • Bitcoin
  • News
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?