• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
CoinLaw LogoCoinLaw

Bringing Crypto & Finance Closer to You

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
CoinLaw Logo
Subscribe To Our Newsletter
Home » Cryptocurrency

Crypto Hackers Exploit Ethereum Smart Contracts in NPM Attacks

Updated on: September 4, 2025
Kathleen Kinder
Written By
Kathleen Kinder
Kathleen Kinder
Senior Editor
Kathleen Kinder brings over 11 years of experience in the research industry, with deep expertise in finance, cryptocurrency, and insurance. ... See full bio
LATEST POSTS:
Optimism Gains as Ether.fi Expands Crypto Cards
Coinbase Expands Loans to XRP, Dogecoin, ADA, LTC
Kresus Raises $13M to Scale Seedless Wallet and Tokenization
Hackers Exploit Ethereum Smart Contracts
As Featured In
FortuneYahoo! FinanceCoinDeskSeeking AlphaCoin Market Cap
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

Hackers have found a new way to deliver malware by hiding malicious links inside Ethereum smart contracts, bypassing traditional security measures.

Key Takeaways

  • Two NPM packages, colortoolsv2 and mimelib2, used Ethereum smart contracts to hide URLs for downloading second-stage malware.
  • This method makes detection difficult by disguising malicious activity as legitimate blockchain traffic.
  • The attack was part of a wider social engineering campaign using fake GitHub repositories to appear trustworthy.
  • Researchers at ReversingLabs said this marks a new evolution in supply chain attacks targeting crypto developers.

What Happened?

A pair of malicious JavaScript packages found on the Node Package Manager (NPM) repository used Ethereum smart contracts to distribute malware. These packages accessed smart contracts to fetch URLs leading to additional payloads, effectively hiding malware download commands within blockchain transactions.

This technique bypassed conventional security tools, which typically do not flag blockchain queries as suspicious.

⚠️ New RL threat research: 2 malicious #npm packages abuse #Ethereum smart contracts to load #malware on compromised devices. https://t.co/wzDRKfm2yh

— ReversingLabs (@ReversingLabs) September 3, 2025

A Sophisticated Attack Vector

Cybersecurity firm ReversingLabs identified the two malicious packages, colortoolsv2 and mimelib2, in July 2025. Though they seemed like basic tools, the packages acted as simple loaders. Instead of embedding harmful code directly, they pulled command-and-control server addresses from Ethereum smart contracts.

Once installed, the malware queried the blockchain to get a URL that then led to the download of the second-stage payload, which executed the malicious activity. The use of Ethereum smart contracts obscures the origin of the malware and allows the malicious code to blend in with ordinary blockchain traffic.

Lucija Valentić, a researcher at ReversingLabs, explained, “This is something we haven’t seen previously. It highlights the fast evolution of detection evasion strategies by malicious actors who are trolling open source repositories and developers.”

More Than Just Malware

This operation was part of a larger deception campaign on GitHub. Hackers set up fake cryptocurrency trading bot repositories that looked authentic, complete with:

  • Fabricated commits
  • Multiple fake user accounts
  • Professional documentation and visuals
  • Artificially inflated stars and watchers

These repositories were designed to lure unsuspecting developers, who might unknowingly integrate malicious packages into their own projects. The attackers successfully combined social engineering with technical stealth, exploiting the trust placed in active-looking GitHub repositories.

Newsletter Img
Don't chase the news. Let us curate it.

You get one weekly briefing with only the stories that matter. If the market is quiet, we skip it.

✅ Join readers from Visa, Vanguard, and the FDIC.

Not Limited to Ethereum

While this attack used Ethereum, other blockchains have been exploited similarly. In April, a fake GitHub repo disguised as a Solana trading bot spread malware that stole crypto wallet credentials. Another attack targeted Bitcoinlib, a Python tool for Bitcoin development.

The threat landscape for open-source crypto development is growing more dangerous. In 2024 alone, over 20 crypto-focused malware campaigns were documented across platforms like NPM and PyPI.

Zhonghui Gu, founder of CertiK and a professor at Columbia University, recently called the cybersecurity situation in crypto an “endless war” against hackers.

CoinLaw’s Takeaway

Honestly, this attack feels like a wake-up call for everyone in the crypto and developer communities. I’ve seen how quickly trust can be abused in the open-source ecosystem. When even basic packages can be backdoors and smart contracts get twisted into malware tools, it’s no longer enough to just scan code for suspicious strings. We need to rethink trust models in blockchain and open-source tooling. In my experience, even seasoned devs can fall for well-crafted deception, especially when it’s dressed up with blockchain buzz. This is a reminder to verify the integrity of both code and its creators.

Read more about Blockchain

Blockchain

Blockchain is a decentralized digital ledger that records transactions across multiple computers, making the data transparent, secure, and tamper-resistant. It powers cryptocurrencies but is also used in supply chains, finance, and many other industries.

Add CoinLaw as a Preferred Source on Google for instant updates! Follow on Google News
Share ChatGPT Perplexity
Kathleen Kinder

Kathleen Kinder

Senior Editor


Kathleen Kinder brings over 11 years of experience in the research industry, with deep expertise in finance, cryptocurrency, and insurance. At CoinLaw, she writes timely, reader-focused news articles and also serves as a senior editorial reviewer. Drawing on her background in B2B research, consumer insights, and executive interviews, she ensures every piece delivers clarity, accuracy, and real-world relevance.

Disclaimer: The content published on CoinLaw is intended solely for informational and educational purposes. It does not constitute financial, legal, or investment advice, nor does it reflect the views or recommendations of CoinLaw regarding the buying, selling, or holding of any assets. All investments carry risk, and you should conduct your own research or consult with a qualified advisor before making any financial decisions. You use the information on this website entirely at your own risk.

Related Posts

Binance Boosts Junior App With Gifting and Merchant Pay
Cryptocurrency

Binance Boosts Junior App With Gifting and Merchant Pay

Phemex Lists Ondo Tokenized Equities With 14 Assets
Cryptocurrency

Phemex Lists Ondo Tokenized Equities With 14 Assets

Optimism Gains as Ether.fi Expands Crypto Cards
Cryptocurrency

Optimism Gains as Ether.fi Expands Crypto Cards

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

BitPay Statistics 2026: Market Growth Revealed
Coinbase Expands Loans to XRP, Dogecoin, ADA, LTC
UAE Quietly Mines and Holds 6,782 BTC Worth $453M

Table of Contents

  • Key Takeaways
  • What Happened?
  • A Sophisticated Attack Vector
  • More Than Just Malware
  • Not Limited to Ethereum
  • CoinLaw’s Takeaway
Connect on Telegram

Footer

CoinLaw Logo

Bringing Finance Closer to You.

Connect With Us

Follow Us on Google News

Site Links

  • About CoinLaw
  • Newsletter
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Worth Checking

  • Debit Card Statistics
  • NFT Market Growth Statistics
  • Retail Investing Statistics
  • Credit Card Fraud Statistics
  • Most Expensive Crypto Scams
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. – 6 p.m. | Every day

Copyright © 2024–2026 CoinLaw. All Rights Reserved. Powered by the HODL Force ❤️

  • Privacy Policy
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • glossary icon
    Glossary
  • Stats
    Stats Research Process
  • Brand Guide Icon
    Brand Assets
Categories
  • Cryptocurrency
  • Payments
  • Finance
  • Banking
  • Insurance
Cryptocurrency
BitPay Statistics
BitPay Statistics 2026: Market Growth Revealed
DMG Blockchain Statistics
DMG Blockchain Statistics 2026: Growth Insights
Binance User Statistics
Binance User Statistics 2026: Growth Secrets
Northern Data Statistics
Northern Data Statistics 2026: Debt & Growth
Ebang International Statistics
Ebang International Statistics 2026: Growth Signals
Sphere 3D Statistics
Sphere 3D Statistics 2026: Market Secrets
Payments
Digital Remittance Statistics
Digital Remittance Statistics 2026: Market Surge Now
BHIM App Statistics
BHIM App Statistics 2026: Real Numbers, Big Impact
Amazon Pay Statistics
Amazon Pay Statistics 2026: Secrets Uncovered
WeChat Statistics
WeChat Statistics 2026: Mind-Blowing New Data
2Checkout Statistics
2Checkout Statistics 2026: Growth Secrets Unveiled
Debit Card Statistics
Debit Card Statistics 2026: Insights That Matter Now
Finance
Diversity In The Finance Industry Statistics
Diversity In The Finance Industry Statistics 2026: Powerful Trends Uncovered
GitHub Statistics
GitHub Statistics 2026: What You Must Know Now
Financial Literacy Statistics
Financial Literacy Statistics 2026: What Most Get Wrong Now
Decentralized Finance Defi Market Statistics
Decentralized Finance (DeFi) Market Statistics 2026: Must-Know Insights Now
Quantum Cryptography in Finance Statistics
Quantum Cryptography in Finance Statistics 2026: Security or Chaos?
Global Household Savings Statistics
Global Household Savings Statistics 2026: See How Your Country Ranks
Banking
Digital Transformation in Banking Statistics
Digital Transformation in Banking Statistics 2026: Growth, Challenges, and Opportunities
Banking Statistics
Banking Statistics 2026: What You Must Know Now
ATM Statistics
ATM Statistics 2026: Insights You Must See Now
Neobank Industry Statistics
Neobank Industry Statistics 2026: Tap Into Explosive Revenue Secrets
UBS Statistics
UBS Statistics 2026: New Data, Big Surprises Ahead
Deutsche Bank Statistics
Deutsche Bank Statistics 2026: Hidden Trends Exposed Now
Insurance
Digital Transformation in Insurance Industry Statistics
Digital Transformation in Insurance Industry Statistics 2026: Market Shift Now
Auto Insurance Industry Statistics
Auto Insurance Industry Statistics 2026: Growth Secrets
AI in Insurance Industry Statistics
AI in Insurance Industry Statistics 2026: Shocking Growth Insights
AI in Insurance Claims Statistics
AI in Insurance Claims Statistics 2026: How AI Wins Big
US Insurance Industry Statistics
US Insurance Industry Statistics 2026: What’s Surging Now
Property and Casualty Insurance Statistics
Property and Casualty Insurance Statistics 2026: Shocking Trends You Must See Now
Categories
  • Cryptocurrency
  • Investments
  • Compliance
  • Fintech
  • Finance
Cryptocurrency
Binance Upgrades Junior App With More Features
Binance Boosts Junior App With Gifting and Merchant Pay
Phemex Lists Ondo Tokenized Equities With 14 Assets
Phemex Lists Ondo Tokenized Equities With 14 Assets
Optimism Gains As Ether Fi Expands Crypto Cards
Optimism Gains as Ether.fi Expands Crypto Cards
Coinbase Expands Loans To Xrp Dogecoin Ada Ltc
Coinbase Expands Loans to XRP, Dogecoin, ADA, LTC
Reports Say Uae Has Mined Btc
UAE Quietly Mines and Holds 6,782 BTC Worth $453M
Rlusd Gains Rwa Yield As Soil Expands To Xrp Ledger
RLUSD Gains RWA Yield as Soil Expands to XRP Ledger
Investments
Kresus Raises 13m To Scale Seedless Wallet And Tokenization
Kresus Raises $13M to Scale Seedless Wallet and Tokenization
Ledn Brings Bitcoin Loans Wrapped As Bonds To Wall Street
Ledn Brings Bitcoin Loans to Wall Street with $188 Million Deal
Kraken Partners With Magna For Token Management
Kraken Deepens Institutional Crypto Offerings with Magna Deal
Ark Invest Buys 6 9m Coinbase Shares After Recent Sales
ARK Invest Buys 6.9M Coinbase Shares After Recent Sales
Softbank Sells 5 8b Of Nvidia Shares
SoftBank Sells 5.8B Nvidia Stake to Fund OpenAI
Pred Raises 2 5m To Build Sports Prediction Exchange
Pred Raises $2.5M to Build Sports Prediction Exchange
Compliance
Hong Kong To Issue Stablecoin Licenses Amid China Crypto Ban
Hong Kong Advances Stablecoin Plans Despite China Ban
Polymarket Sues Massachusetts Over Sports Prediction Ban
Polymarket Sues Massachusetts Over Sports Prediction Ban
China Bans Crypto Issuance By Domestic Firms Overseas
China Bans Crypto Issuance by Domestic Firms Overseas
Wlfi Faces House Probe Over 500m Uae Royal Investment
WLFI Faces House Probe Over $500M UAE Royal Investment
South Korea Probes Zksync Price Surge On Upbit
South Korea Probes ZKsync Price Surge on Upbit
Nevada Sues Coinbase Over Unlicensed Predictions Market
Nevada Sues Coinbase Over Unlicensed Prediction Markets
Fintech
Substack Partners With Polymarket For Live Prediction Markets
Substack Partners With Polymarket for Live Prediction Markets
Quantoz Secures Visa Deal For Stablecoin Payments Card
Quantoz Secures Visa Deal for Stablecoin Payments Card
Coinfello Debuts Ai Smart Contract Agent At Ethdenver
CoinFello Debuts AI Smart Contract Agent at ETHDenver Conference
X Plans In App Stock And Crypto Trading
X Plans In App Stock and Crypto Trading With Smart Cashtags Launch
Uk Treasury Taps Hsbc For Bond Tokenization
UK Treasury Taps HSBC for Blockchain Based Sovereign Bond Pilot
Eu Moves Forward With Ecb Digital Euro Proposal
EU Moves Forward With ECB Digital Euro Proposal
Finance
Bitcoin Crash Hits Galaxy Digital Hard With 482m Q4 Loss
Bitcoin Crash Hits Galaxy Digital Hard with $482M Q4 Loss
Ripple Cleared For Eu Expansion With Full Luxembourg Emi License
Ripple Cleared for EU Expansion with Full Luxembourg EMI License
Chainlink Etf By Bitwise Goes Live On Nyse
Chainlink Gets a Wall Street Gateway as Bitwise Spot ETF Hits NYSE
Pharos Foundation Live For Open Finance
Pharos Foundation Debuts to Drive Institutional Adoption of Open Finance
Gemini Posts Lackluster Q3 Results After Ipo
Gemini’s First Post-IPO Report Shows Revenue Growth but Mounting Losses
Coinbase Posts Profit In Q3 Results
Coinbase Posts $433M Profit as Trading and Subscriptions Surge in Q3
Newsletter Img

Too much noise in crypto?

We respect your time. You get one high-impact briefing a week. If the market is quiet, so are we.

✅ Join readers from Visa, Vanguard, and the FDIC.
Newsletter Img

The Weekly Briefing

We track the market 24/7. You get a 5-minute summary. If it’s quiet, we skip it.

✅ Read by pros at Visa, Vanguard, and the FDIC.