• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Threat Actors Use Ethereum Smart Contracts to Deliver Malware in Evolving Attack Strategy
Share
  • bitcoinBitcoin(BTC)$67,704.00
  • ethereumEthereum(ETH)$2,059.33
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$618.73
  • rippleXRP(XRP)$1.36
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$84.22
  • tronTRON(TRX)$0.321692
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02
  • dogecoinDogecoin(DOGE)$0.093371
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
Ethereum

Threat Actors Use Ethereum Smart Contracts to Deliver Malware in Evolving Attack Strategy

News Desk
Last updated: September 4, 2025 5:07 am
News Desk
Published: September 4, 2025
Share
01991283 4d0c 73ac 8323 3c96bbb3b4e3

Recent research from ReversingLabs has unveiled a sophisticated method employed by threat actors to deliver malware using Ethereum smart contracts. This innovative approach aims to bypass security scans and highlights an alarming evolution in cyber attack strategies targeting code repositories.

According to ReversingLabs, two malicious packages found on the Node Package Manager (NPM), designated as “colortoolsv2” and “mimelib2,” have been utilizing smart contracts on the Ethereum blockchain to conceal malevolent commands. Released in July, these packages function as downloaders that initially appear harmless. Instead of hosting malicious links directly, they cleverly retrieve command and control server addresses from smart contracts when installed on compromised systems.

Lucija Valentić, a ReversingLabs researcher, noted in a recent blog post that when these packages are operational, they query the blockchain to obtain URLs leading to the download of secondary malware. This technique complicates detection efforts because the blockchain transactions appear legitimate, complicating efforts to identify and nullify threats.

While malware targeting Ethereum smart contracts isn’t entirely new—earlier this year, the Lazarus Group, linked to North Korean hacking activities, employed similar tactics—the strategic use of smart contracts to host URLs for downloading malware marks a notable shift. Valentić emphasized that this novel approach underscores the rapid evolution of evasion tactics utilized by malicious actors, particularly in the context of open-source repositories.

The research reveals that these malware packages are part of a broader deception campaign primarily orchestrated through GitHub. Cybercriminals have developed fake cryptocurrency trading bot repositories designed to instill confidence among potential victims. This intricate operation involves fabricated commits, the creation of misleading user accounts to monitor repositories, multiple maintainer accounts designed to project active development, and professional-quality project documentation.

The investigation into these threats comes amid an increasing number of malicious campaigns targeting cryptocurrency users. In 2024 alone, researchers have identified 23 crypto-related malicious efforts linked to open-source repositories. The latest developments reveal the ability of attackers to blend blockchain technology with intricate social engineering, enhancing their chances of evading traditional detection methods.

This evolving threat landscape extends beyond Ethereum. For example, earlier in April, a deceptive repository masquerading as a Solana trading bot was discovered to distribute malware capable of stealing credentials from crypto wallets. Additionally, attacks have also been reported targeting “Bitcoinlib,” an open-source Python library aimed at simplifying Bitcoin development.

As cyber threats continue to advance and exploit newfound vulnerabilities, experts urge users to remain vigilant and adopt robust cybersecurity practices when engaging with open-source repositories and cryptocurrency technologies.

Whale Moves 1,176 Bitcoin Worth $136 Million to Hyperliquid Trading Platform
Grayscale’s Ethereum Trust Receives Approval for NYSE Arca Listing
Kraken Expands xStocks to Ethereum for Enhanced Tokenized Stock Access
Bitcoin Upgrade BRC-2.0 Introduces Programmability, Paving the Way for DeFi and NFTs
Vitalik Buterin Warns Against Using AI for Governance Due to Exploitation Risks
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article Blockchain Illustration DICT Secretary Aguda Supports Senator Aquino’s Blockchain Bill for Enhanced Budget Transparency
Next Article 01957079 b2a5 716c 8d1f fba6f23044bf Bitcoin Adoption on the Rise as Businesses Reinvest Profits
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
108283776 1774564238270 gettyimages 2265155339 US STOCKS
European Stocks Drop Amid Escalating Iran Conflict
1760632538 news story
Bitcoin’s Slide Raises Concerns Over Potential Six-Month Losing Streak
8cc367192e502242d8fbbe4724365d99
Bitget Enhances Trading Experience with Deeper Integration with TradingView
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Company
  • Finance
  • Stocks
  • News
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?