• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
CoinLaw LogoCoinLaw

Bringing Crypto & Finance Closer to You

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
CoinLaw Logo
Subscribe To Our Newsletter
Home Β» Cryptocurrency

Crypto Hackers Exploit Ethereum Smart Contracts in NPM Attacks

Updated on: September 4, 2025
Kathleen Kinder
Written By
Kathleen Kinder
Kathleen Kinder
Senior Editor
Kathleen Kinder brings over 11 years of experience in the research industry, with deep expertise in finance, cryptocurrency, and insurance. ... See full bio
LATEST POSTS:
Tesla Secures SpaceX Stake After xAI Merger Before IPO
BlackRock Launches Ethereum Staking ETF ETHB on Nasdaq
Wizz Financial Launches Stablecoin Payments to 80 Countries
Hackers Exploit Ethereum Smart Contracts
As Featured In
FortuneYahoo! FinanceCoinDeskSeeking AlphaCoin Market Cap
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

Hackers have found a new way to deliver malware by hiding malicious links inside Ethereum smart contracts, bypassing traditional security measures.

Key Takeaways

  • Two NPM packages, colortoolsv2 and mimelib2, used Ethereum smart contracts to hide URLs for downloading second-stage malware.
  • This method makes detection difficult by disguising malicious activity as legitimate blockchain traffic.
  • The attack was part of a wider social engineering campaign using fake GitHub repositories to appear trustworthy.
  • Researchers at ReversingLabs said this marks a new evolution in supply chain attacks targeting crypto developers.

What Happened?

A pair of malicious JavaScript packages found on the Node Package Manager (NPM) repository used Ethereum smart contracts to distribute malware. These packages accessed smart contracts to fetch URLs leading to additional payloads, effectively hiding malware download commands within blockchain transactions.

This technique bypassed conventional security tools, which typically do not flag blockchain queries as suspicious.

⚠️ New RL threat research: 2 malicious #npm packages abuse #Ethereum smart contracts to load #malware on compromised devices. https://t.co/wzDRKfm2yh

β€” ReversingLabs (@ReversingLabs) September 3, 2025

A Sophisticated Attack Vector

Cybersecurity firm ReversingLabs identified the two malicious packages, colortoolsv2 and mimelib2, in July 2025. Though they seemed like basic tools, the packages acted as simple loaders. Instead of embedding harmful code directly, they pulled command-and-control server addresses from Ethereum smart contracts.

Once installed, the malware queried the blockchain to get a URL that then led to the download of the second-stage payload, which executed the malicious activity. The use of Ethereum smart contracts obscures the origin of the malware and allows the malicious code to blend in with ordinary blockchain traffic.

Lucija ValentiΔ‡, a researcher at ReversingLabs, explained, “This is something we haven’t seen previously. It highlights the fast evolution of detection evasion strategies by malicious actors who are trolling open source repositories and developers.”

More Than Just Malware

This operation was part of a larger deception campaign on GitHub. Hackers set up fake cryptocurrency trading bot repositories that looked authentic, complete with:

  • Fabricated commits
  • Multiple fake user accounts
  • Professional documentation and visuals
  • Artificially inflated stars and watchers

These repositories were designed to lure unsuspecting developers, who might unknowingly integrate malicious packages into their own projects. The attackers successfully combined social engineering with technical stealth, exploiting the trust placed in active-looking GitHub repositories.

Newsletter Img
Don't chase the news. Let us curate it.

You get one weekly briefing with only the stories that matter. If the market is quiet, we skip it.

βœ… Join readers from Visa, Vanguard, and the FDIC.

Not Limited to Ethereum

While this attack used Ethereum, other blockchains have been exploited similarly. In April, a fake GitHub repo disguised as a Solana trading bot spread malware that stole crypto wallet credentials. Another attack targeted Bitcoinlib, a Python tool for Bitcoin development.

The threat landscape for open-source crypto development is growing more dangerous. In 2024 alone, over 20 crypto-focused malware campaigns were documented across platforms like NPM and PyPI.

Zhonghui Gu, founder of CertiK and a professor at Columbia University, recently called the cybersecurity situation in crypto an β€œendless war” against hackers.

CoinLaw’s Takeaway

Honestly, this attack feels like a wake-up call for everyone in the crypto and developer communities. I’ve seen how quickly trust can be abused in the open-source ecosystem. When even basic packages can be backdoors and smart contracts get twisted into malware tools, it’s no longer enough to just scan code for suspicious strings. We need to rethink trust models in blockchain and open-source tooling. In my experience, even seasoned devs can fall for well-crafted deception, especially when it’s dressed up with blockchain buzz. This is a reminder to verify the integrity of both code and its creators.

Add CoinLaw as a Preferred Source on Google for instant updates! Follow on Google News
Share ChatGPT Perplexity
Kathleen Kinder

Kathleen Kinder

Senior Editor


Kathleen Kinder brings over 11 years of experience in the research industry, with deep expertise in finance, cryptocurrency, and insurance. At CoinLaw, she writes timely, reader-focused news articles and also serves as a senior editorial reviewer. Drawing on her background in B2B research, consumer insights, and executive interviews, she ensures every piece delivers clarity, accuracy, and real-world relevance.

Disclaimer:Β The content published on CoinLaw is intended solely for informational and educational purposes. It does not constitute financial, legal, or investment advice, nor does it reflect the views or recommendations of CoinLaw regarding the buying, selling, or holding of any assets. All investments carry risk, and you should conduct your own research or consult with a qualified advisor before making any financial decisions. You use the information on this website entirely at your own risk.

Related Posts

Trust Wallet Hack Hits Hundreds, $7 Million Stolen in Browser Extension Breach
Cryptocurrency

Trust Wallet Hack Hits Hundreds, $7 Million Stolen in Browser Extension Breach

Most Expensive Crypto Scams: The Craziest Cases That Fooled the World
Cryptocurrency

Most Expensive Crypto Scams: The Craziest Cases That Fooled the World

Coinbase Loses $300K in Token Fees After MEV Bot Exploit
Cryptocurrency

Coinbase Loses $300K in Token Fees After MEV Bot Exploit

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

Malware in Crypto Smart Contracts 2026: Critical Mistakes to Avoid
$300M Coinbase Hack Wallet Accumulates 3,976 ETH Despite Two-Week High price
Smart Contract Bug Bounties Statistics 2026: Hidden Risks Now

Table of Contents

  • Key Takeaways
  • What Happened?
  • A Sophisticated Attack Vector
  • More Than Just Malware
  • Not Limited to Ethereum
  • CoinLaw’s Takeaway
Connect on Telegram

Footer

CoinLaw Logo

Bringing Finance Closer to You.

Connect With Us

Follow Us on Google News

Site Links

  • About CoinLaw
  • Newsletter
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Worth Checking

  • Debit Card Statistics
  • NFT Market Growth Statistics
  • Retail Investing Statistics
  • Credit Card Fraud Statistics
  • Most Expensive Crypto Scams
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10β€―a.m. – 6β€―p.m. | Every day

Copyright Β© 2024–2026 CoinLaw. All Rights Reserved. Powered by the HODL Force ❀️

  • Privacy Policy
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • glossary icon
    Glossary
  • Stats
    Stats Research Process
  • Brand Guide Icon
    Brand Assets
Categories
  • Cryptocurrency
  • Payments
  • Finance
  • Banking
  • Insurance
Cryptocurrency
Metaplanet Statistics
Metaplanet Statistics 2026: Explosive BTC Growth
INX Digital Statistics
INX Digital Statistics 2026: Powerful Market Insights
Transak Statistics
Transak Statistics 2026: Key Metrics You Must See Now
WonderFi Statistics
WonderFi Statistics 2026: Growth Exposed
Digital Currency Statistics
Digital Currency Statistics 2026: Global Surge Now
Cryptocurrency Mining Statistics
Cryptocurrency Mining Statistics 2026: Energy, Profits & Risks
Payments
Payment Processing Solutions Statistics
Payment Processing Solutions Statistics 2026: Fintech Growth
Online Payment Statistics
Online Payment Statistics 2026: Explosive Growth
Money Transfer Industry Statistics
Money Transfer Industry Statistics 2026: Global Surge Now
Mobile Wallet Industry Statistics
Mobile Wallet Industry Statistics 2026: User Growth Trends
Merchant Services Industry Statistics
Merchant Services Industry Statistics 2026: Innovations, Payments, and Security
Mastercard Statistics
Mastercard Statistics 2026: Global Spending Trends Now
Finance
Personal Finance App Industry Statistics
Personal Finance App Industry Statistics 2026: Smart Money Apps Now
Inflation Statistics
Inflation Statistics 2026: Latest Trends, Comparisons, and Economic Impacts
Foreign Exchange Industry Statistics
Foreign Exchange Industry Statistics 2026: Who Controls FX Now?
Financial Planning Industry Statistics
Financial Planning Industry Statistics 2026: Powerful Market Insights
Finance Industry Statistics
Finance Industry Statistics 2026: Powerful Insights
Diversity In The Finance Industry Statistics
Diversity In The Finance Industry Statistics 2026: Powerful Trends Uncovered
Banking
JPMorgan Chase Statistics
JPMorgan Chase Statistics 2026: Growth Insights
Online Banking Usage Statistics
Online Banking Usage Statistics 2026: Shocking Growth
Digital Transformation in Banking Statistics
Digital Transformation in Banking Statistics 2026: Growth, Challenges, and Opportunities
Banking Statistics
Banking Statistics 2026: What You Must Know Now
ATM Statistics
ATM Statistics 2026: Insights You Must See Now
Neobank Industry Statistics
Neobank Industry Statistics 2026: Tap Into Explosive Revenue Secrets
Insurance
Pet Insurance Industry Statistics
Pet Insurance Industry Statistics 2026: Growth, Costs, and Coverage
Parametric Insurance Industry Statistics
Parametric Insurance Industry Statistics 2026: Payout Trends Now
Motorcycle Insurance Industry Statistics
Motorcycle Insurance Industry Statistics 2026: Growth Report
Insurtech Statistics
Insurtech Statistics 2026: Explosive Market Growth
Home Insurance Industry Statistics
Home Insurance Industry Statistics 2026: Growth Forecast
Embedded Insurance Industry Statistics
Embedded Insurance Industry Statistics 2026: Hidden Opportunities
Categories
  • Cryptocurrency
  • Investments
  • Compliance
  • Fintech
  • Finance
Cryptocurrency
Blackrock Launches Ethereum Staking Etf Ethb On Nasdaq
BlackRock Launches Ethereum Staking ETF ETHB on Nasdaq
Wizz Financial Launches Stablecoin Payments With Bitgo
Wizz Financial Launches Stablecoin Payments to 80 Countries
South Korea Ai Crypto Tax Reporting
South Korea to Use AI to Track Crypto Taxes by 2027
Binance Wins Anti Terrorism Connections Case
US Courts Dismiss Anti-Terrorism Claims Against Binance
Grayscale Debuts Avax Staking Etf On Nasdaq
Grayscale Debuts AVAX Avalanche Staking ETF on Nasdaq
Metaplanet Announces New Ventures
Metaplanet Expands Bitcoin Push With Ventures and Asset Unit
Investments
Tesla Secures Spacex Stake After Xai Merger
Tesla Secures SpaceX Stake After xAI Merger Before IPO
Tether Invest In Ark Labs For Bitcoin Stablecoin
Tether Joins $5.2M Ark Labs Round to Build Stablecoins on Bitcoin
Nvidia And Nebius Partner On Next Gen Ai Cloud Platform
Nvidia and Nebius Partner on Next Gen AI Cloud Platform
Ripple Plans 750m Buyback Program
Ripple Plans $750M Buyback as Valuation Hits $50B
Strive Buys Strategy Shares With Bitcoin Puchase
Strive Boosts SATA Dividend and Adds $50M of Strategy STRC
Bitgo Backs Ubyx As Settlement Agent
BitGo Backs Ubyx as Settlement Agent for Digital Assets
Compliance
Bithumb Faces Six Month Suspension Over Aml Compliance Issues
Bithumb Faces Six Month Suspension Over AML Violations
Dubai Authorities Send Cease And Desist To Kucoin Exchange
Dubai Regulator Orders KuCoin to Halt Crypto Services
Trump Criticizes Bank For Clarity Act Delays
Trump Pressures Banks as Crypto Clarity Act Stalls in Senate
Crypto Com Wins Financial License In Malta
Crypto.com Boosts EU Compliance With New MFSA Licence
Occ Proposes New Stablecoin Rules Under Genius Act
OCC Proposes New Stablecoin Rules Under GENIUS Act
Pakistan Enables The Regulatory Crypto Sandbox
Pakistan Advances Digital Asset Regulation With Crypto Sandbox
Fintech
Dia Launches New Blockchain Oracle
DIA Targets $100 Billion DeFi Pricing Gap With New Value Oracle
Crypto Com Joins Broadridge Nyfix Network
Crypto.com Joins Broadridge NYFIX Network for Institutional Trading
Starcloud Plans Bitcoin Mining In Space
Nvidia Backed Starcloud Plans Bitcoin Mining in Space
Visa And Bridge Partner For Stablecoin Network
Visa and Bridge Take Stablecoin Cards Global
Nasdaq Plans Binary Options On Platform
Nasdaq Plans Yes or No Options on Nasdaq 100
Numo Launches Bitcoin Tap To Pay App For Merchants
Numo Launches Bitcoin Tap-to-Pay App for Merchants
Finance
21shares Launches Strategy Yield Etp
21Shares Rolls Out Strategy Yield ETP on Euronext Amsterdam
Yahoo Finance Adds Coinbase Trading
Yahoo Finance Adds Coinbase Trading as Stock Rollout Expands
Bitcoin Crash Hits Galaxy Digital Hard With 482m Q4 Loss
Bitcoin Crash Hits Galaxy Digital Hard with $482M Q4 Loss
Ripple Cleared For Eu Expansion With Full Luxembourg Emi License
Ripple Cleared for EU Expansion with Full Luxembourg EMI License
Chainlink Etf By Bitwise Goes Live On Nyse
Chainlink Gets a Wall Street Gateway as Bitwise Spot ETF Hits NYSE
Pharos Foundation Live For Open Finance
Pharos Foundation Debuts to Drive Institutional Adoption of Open Finance
Newsletter Img

Too much noise in crypto?

We respect your time. You get one high-impact briefing a week. If the market is quiet, so are we.

βœ… Join readers from Visa, Vanguard, and the FDIC.
Newsletter Img

The Weekly Briefing

We track the market 24/7. You get a 5-minute summary. If it’s quiet, we skip it.

βœ… Read by pros at Visa, Vanguard, and the FDIC.