• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Researchers Uncover NPM Packages Using Blockchain to Deliver Malware
Share
  • bitcoinBitcoin(BTC)$115,590.00
  • ethereumEthereum(ETH)$4,508.88
  • rippleXRP(XRP)$3.04
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$905.02
  • solanaSolana(SOL)$232.13
  • usd-coinUSDC(USDC)$1.00
  • dogecoinDogecoin(DOGE)$0.259728
  • staked-etherLido Staked Ether(STETH)$4,502.75
  • tronTRON(TRX)$0.348352
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
Ethereum

Researchers Uncover NPM Packages Using Blockchain to Deliver Malware

News Desk
Last updated: September 4, 2025 11:50 am
News Desk
Published: September 4, 2025
Share
ethereum 3660218 1280

Cybersecurity experts have identified a sophisticated method employed by hackers to deliver malware through the use of compromised NPM packages, which harness blockchain queries to disguise malicious URLs as part of legitimate traffic. The discovery, made by ReversingLabs, focuses on two specific NPM packages—‘colortoolsv2’ and ‘mimelib2’—that were uploaded to the widely used Node Package Manager repository in July.

These packages exploit the capabilities of Ethereum smart contracts to fetch URLs leading to downloader malware. By embedding command and control addresses within the blockchain traffic, attackers successfully circumvent traditional security scans, making their malicious activities appear as benign transactions.

This development is part of a larger deception campaign. The attackers have created fake GitHub repositories that masquerade as cryptocurrency trading bots, complete with counterfeit commits, fabricated user accounts, and professional-looking documentation. This strategy is designed to lure unsuspecting developers into using their compromised software.

The trend is a concerning one, as experts have noted that similar campaigns have extended to include targets within Solana and Bitcoin-related libraries, indicating a broader evolution in cyber threats. The implications of these findings raise important questions regarding the security of software development ecosystems and the need for vigilant practices among developers.

Etherealize Raises $40 Million to Bring Ethereum to Wall Street
Malicious npm Packages Discovered Stealing Ethereum Developers’ Cryptocurrency Wallet Credentials
Ethereum ETFs Face Significant Outflows Amidst Market Correction
US Equities Reach New Heights Following CPI Release Amid Mixed Cryptocurrency Performance
Ethereum Whales Accumulate 260,000 ETH Amid Price Correction, Spark Bullish Outlook
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article 46bc364ae9db695cf12080a24a697f2e.webp Datavault AI Inc. Recognized in Forbes for Pioneering AI and Web3 Integration
Next Article xrp defi flare partnership secure on chain yield cropped.webp Can XRP Replace SWIFT in Global Payments?
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
Comp c0b97c
Wall Street Trader Hits $5 Million Jackpot Betting on Warner Bros Stock Before Paramount Bid News
chainlink ubs and digift launch tokenized fund automation
Chainlink, UBS, and DigiFT Collaborate to Automate Tokenized Fund Management in Hong Kong
0902 Q1920Total20Markets20photos20and20gif CC8
General Dynamics Stock Rises Ahead of Earnings Report
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Finance
  • News
  • Company
  • Bitcoin
  • Ethereum
  • XRP
  • Altcoins
  • DeFi
  • Blockchain
  • Stocks
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?