• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
CoinLaw LogoCoinLaw

Bringing Crypto and Finance Closer to You

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
CoinLaw Logo
  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Home » Cryptocurrency

Crypto Hackers Exploit Ethereum Smart Contracts in NPM Attacks

Published on: September 4, 2025
Kathleen Kinder
Written By
Kathleen Kinder
Kathleen Kinder
Senior Editor • 1,702 Articles
Kathleen Kinder brings over 11 years of experience in the research industry, with deep expertise in finance, cryptocurrency, and insurance. ... See full bio
LATEST POSTS:
Morpho Raises $175M at $2B Value as MORPHO Token Jumps
South Korea Taps Chainalysis to Tackle Crypto Crime
Pyth Launches Groundbreaking 24/7 Stock and Commodity Indices
Hackers Exploit Ethereum Smart Contracts
As Featured In
FortuneYahoo! FinanceCoinDeskSeeking AlphaCoin Market Cap
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

Hackers have found a new way to deliver malware by hiding malicious links inside Ethereum smart contracts, bypassing traditional security measures.

Key Takeaways

  • Two NPM packages, colortoolsv2 and mimelib2, used Ethereum smart contracts to hide URLs for downloading second-stage malware.
  • This method makes detection difficult by disguising malicious activity as legitimate blockchain traffic.
  • The attack was part of a wider social engineering campaign using fake GitHub repositories to appear trustworthy.
  • Researchers at ReversingLabs said this marks a new evolution in supply chain attacks targeting crypto developers.

What Happened?

A pair of malicious JavaScript packages found on the Node Package Manager (NPM) repository used Ethereum smart contracts to distribute malware. These packages accessed smart contracts to fetch URLs leading to additional payloads, effectively hiding malware download commands within blockchain transactions.

This technique bypassed conventional security tools, which typically do not flag blockchain queries as suspicious.

⚠️ New RL threat research: 2 malicious #npm packages abuse #Ethereum smart contracts to load #malware on compromised devices. https://t.co/wzDRKfm2yh

— ReversingLabs (@ReversingLabs) September 3, 2025

A Sophisticated Attack Vector

Cybersecurity firm ReversingLabs identified the two malicious packages, colortoolsv2 and mimelib2, in July 2025. Though they seemed like basic tools, the packages acted as simple loaders. Instead of embedding harmful code directly, they pulled command-and-control server addresses from Ethereum smart contracts.

Once installed, the malware queried the blockchain to get a URL that then led to the download of the second-stage payload, which executed the malicious activity. The use of Ethereum smart contracts obscures the origin of the malware and allows the malicious code to blend in with ordinary blockchain traffic.

Lucija Valentić, a researcher at ReversingLabs, explained, “This is something we haven’t seen previously. It highlights the fast evolution of detection evasion strategies by malicious actors who are trolling open source repositories and developers.”

More Than Just Malware

This operation was part of a larger deception campaign on GitHub. Hackers set up fake cryptocurrency trading bot repositories that looked authentic, complete with:

  • Fabricated commits
  • Multiple fake user accounts
  • Professional documentation and visuals
  • Artificially inflated stars and watchers

These repositories were designed to lure unsuspecting developers, who might unknowingly integrate malicious packages into their own projects. The attackers successfully combined social engineering with technical stealth, exploiting the trust placed in active-looking GitHub repositories.

Newsletter Img
Don't chase the news. Let us curate it.

You get one weekly briefing with only the stories that matter. If the market is quiet, we skip it.

✅ Join readers from Visa, Vanguard, and the FDIC.

Not Limited to Ethereum

While this attack used Ethereum, other blockchains have been exploited similarly. In April, a fake GitHub repo disguised as a Solana trading bot spread malware that stole crypto wallet credentials. Another attack targeted Bitcoinlib, a Python tool for Bitcoin development.

The threat landscape for open-source crypto development is growing more dangerous. In 2024 alone, over 20 crypto-focused malware campaigns were documented across platforms like NPM and PyPI.

Zhonghui Gu, founder of CertiK and a professor at Columbia University, recently called the cybersecurity situation in crypto an “endless war” against hackers.

CoinLaw’s Takeaway

Honestly, this attack feels like a wake-up call for everyone in the crypto and developer communities. I’ve seen how quickly trust can be abused in the open-source ecosystem. When even basic packages can be backdoors and smart contracts get twisted into malware tools, it’s no longer enough to just scan code for suspicious strings. We need to rethink trust models in blockchain and open-source tooling. In my experience, even seasoned devs can fall for well-crafted deception, especially when it’s dressed up with blockchain buzz. This is a reminder to verify the integrity of both code and its creators.

Definition of Smart Contract. Link to full glossary entry follows the description.Smart Contract

A smart contract is a self-executing program stored on a blockchain that automatically enforces agreement terms when predefined conditions are met, without intermediaries.

Read more

CoinLaw follows strict Publishing Principles and a documented Fact-Check Policy to ensure accuracy, transparency, and editorial independence across all content.

Add CoinLaw as a Preferred Source on Google for instant updates! Follow on Google News
Share ChatGPT Perplexity
Kathleen Kinder

Kathleen Kinder

Senior Editor


Kathleen Kinder brings over 11 years of experience in the research industry, with deep expertise in finance, cryptocurrency, and insurance. At CoinLaw, she writes timely, reader-focused news articles and also serves as a senior editorial reviewer. Drawing on her background in B2B research, consumer insights, and executive interviews, she ensures every piece delivers clarity, accuracy, and real-world relevance.

Related Posts

Trust Wallet Hack Hits Hundreds, $7 Million Stolen in Browser Extension Breach
Cryptocurrency

Trust Wallet Hack Hits Hundreds, $7 Million Stolen in Browser Extension Breach

Ripple Shares DPRK Hacker Intel After $577M Crypto Hacks
Cryptocurrency

Ripple Shares DPRK Hacker Intel After $577M Crypto Hacks

Cryptocurrency Security and Fraud Statistics 2026: Big Threats
Cryptocurrency

Cryptocurrency Security and Fraud Statistics 2026: Big Threats

Disclaimer: The content published on CoinLaw is intended solely for informational and educational purposes. It does not constitute financial, legal, or investment advice, nor does it reflect the views or recommendations of CoinLaw regarding the buying, selling, or holding of any assets. All investments carry risk, and you should conduct your own research or consult with a qualified advisor before making any financial decisions. You use the information on this website entirely at your own risk.

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

Malware in Crypto Smart Contracts Statistics 2026: Critical Mistakes to Avoid
$300M Coinbase Hack Wallet Accumulates 3,976 ETH Despite Two-Week High price
Smart Contract Bug Bounties Statistics 2026: Hidden Risks Now

Table of Contents

  • Key Takeaways
  • What Happened?
  • A Sophisticated Attack Vector
  • More Than Just Malware
  • Not Limited to Ethereum
  • CoinLaw’s Takeaway
Connect on Telegram

Footer

CoinLaw Logo

Bringing Finance Closer to You.

Connect With Us

Follow Us on Google News

Editorial & Trust

  • About
  • Publishing Principles
  • Fact-Check Policy
  • Corrections Policy
  • Ethics Policy
  • Disclaimer

Worth Checking

  • Ethereum Gas Fees Statistics
  • Zelle vs. Venmo Statistics
  • Millennial vs. Gen Z Banking
  • Binance vs. Coinbase Statistics
  • Traditional Banks vs. Neobanks
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. – 6 p.m. | Every day

Copyright © 2024–2026 CoinLaw. All Rights Reserved. Powered by the HODL Force ❤️

  • Privacy Policy
  • Terms
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • glossary icon
    Glossary
  • Stats
    Stats Research Process
  • Brand Guide Icon
    Brand Assets
Categories
  • Cryptocurrency
  • Payments
  • Finance
  • Banking
  • Insurance
Cryptocurrency
Coinbase vs Kraken Statistics 2026: Volume, Fees, Licenses
Coinbase vs Kraken Statistics 2026: Volume, Fees, Licenses
Solana vs Ethereum Statistics 2026: TVL, Fees, Validators, ETFs
Solana vs Ethereum Statistics 2026: TVL, Fees, Validators, ETFs
Uniswap vs PancakeSwap Statistics 2026: Head-to-Head DEX Data
Uniswap vs PancakeSwap Statistics 2026: Head-to-Head DEX Data
Cryptojacking Statistics 2026: 80+ Cloud, Cost & Threat Numbers
Cryptojacking Statistics 2026: 80+ Cloud, Cost & Threat Numbers
MetaMask vs Phantom Wallet Statistics 2026: Big Growth Data
MetaMask vs Phantom Wallet Statistics 2026: Big Growth Data
Crypto Wallet Ecosystem Statistics 2026: Addresses, Security, Adoption
Crypto Wallet Ecosystem Statistics 2026: Addresses, Security, Adoption
Payments
Toast Statistics 2026: ARR, GPV & Revenue Data
Toast Statistics 2026: ARR, GPV & Revenue Data
Rapyd Statistics 2026: TPV, Valuation & Licences
Rapyd Statistics 2026: TPV, Valuation & Licences
Marqeta Statistics 2026: TPV, Revenue and Customer Mix
Marqeta Statistics 2026: TPV, Revenue and Customer Mix
Digital Payments Statistics 2026: Market Size, Users, and Growth
Digital Payments Statistics 2026: Market Size, Users, and Growth
Cash App vs Venmo vs Zelle Statistics 2026: What You Must Know Now
Cash App vs Venmo vs Zelle Statistics 2026: What You Must Know Now
Worldpay Statistics 2026: Massive Payment Growth
Worldpay Statistics 2026: Massive Payment Growth
Finance
Emergency Fund Statistics 2026: How Much Americans Have Saved (and How Much They Should)
Emergency Fund Statistics 2026: How Much Americans Have Saved (and How Much They Should)
Financial Advisor Statistics 2026: Headcount, AUM, and Demographics
Financial Advisor Statistics 2026: Headcount, AUM, and Demographics
Wealth Inequality Statistics 2026: Hidden Wealth Divide
Wealth Inequality Statistics 2026: Hidden Wealth Divide
Blockchain in Supply Chain Finance Statistics 2026: Trade Breakthrough
Blockchain in Supply Chain Finance Statistics 2026: Trade Breakthrough
Blockchain in Healthcare Finance Statistics 2026: Cost Breakthrough
Blockchain in Healthcare Finance Statistics 2026: Cost Breakthrough
AI-Powered Robo Trading Statistics 2026: Big Insights
AI-Powered Robo Trading Statistics 2026: Big Insights
Banking
N26 Statistics 2026: Customers, Deposits, Revenue and the BaFin Growth Cap
N26 Statistics 2026: Customers, Deposits, Revenue and the BaFin Growth Cap
Revolut vs Monzo Statistics 2026: Customers & Profit
Revolut vs Monzo Statistics 2026: Customers & Profit
Islamic Banking Statistics 2026: Assets, Growth, and Top Markets
Islamic Banking Statistics 2026: Assets, Growth, and Top Markets
Credit Union Statistics 2026: Assets, Members, Loans
Credit Union Statistics 2026: Assets, Members, Loans
Banking API Statistics 2026: Market Size, Adoption, and Growth
Banking API Statistics 2026: Market Size, Adoption, and Growth
Citigroup Statistics 2026: Growth Secrets Inside
Citigroup Statistics 2026: Growth Secrets Inside
Insurance
Lemonade Insurance Statistics 2026: Customers, In-Force Premium, Loss Ratio, Pet & Auto Segments
Lemonade Insurance Statistics 2026: Customers, In-Force Premium, Loss Ratio, Pet & Auto Segments
Chubb Statistics 2026: Powerful Data Insights
Chubb Statistics 2026: Powerful Data Insights
Virtual Reality In Insurance Statistics 2026: Innovations, Risks, and Opportunities
Virtual Reality In Insurance Statistics 2026: Innovations, Risks, and Opportunities
US Life Insurance Industry Statistics 2026: Growth Facts
US Life Insurance Industry Statistics 2026: Growth Facts
US Auto Insurance Industry Statistics 2026: What You Must Know Now
US Auto Insurance Industry Statistics 2026: What You Must Know Now
UK Insurance Industry Statistics 2026: Growth Data
UK Insurance Industry Statistics 2026: Growth Data
Categories
  • Cryptocurrency
  • Investments
  • Compliance
  • Fintech
  • Finance
Cryptocurrency
South Korea Taps Chainalysis to Tackle Crypto Crime
South Korea Taps Chainalysis to Tackle Crypto Crime
Japan’s Banking Giants Join Forces for Massive Stablecoin Launch
Japan’s Banking Giants Join Forces for Massive Stablecoin Launch
BitMine Deepens Ethereum Bet With Fresh $123M ETH Acquisition
BitMine Deepens Ethereum Bet With Fresh $123M ETH Acquisition
Botanix Abandons Bitcoin Layer 2 After Four Year Bet
Botanix Abandons Bitcoin Layer 2 After Four Year Bet
CME Launches Nasdaq Crypto Index Futures for Institutions
CME Launches Nasdaq Crypto Index Futures for Institutions
FanDuel Expands Prediction Markets With Crypto.com Partnership
FanDuel Expands Prediction Markets With Crypto.com Partnership
Investments
Morpho Raises $175M at $2B Value as MORPHO Token Jumps
Morpho Raises $175M at $2B Value as MORPHO Token Jumps
Pyth Launches Groundbreaking 24/7 Stock and Commodity Indices
Pyth Launches Groundbreaking 24/7 Stock and Commodity Indices
Nvidia Secures SK Hynix AI Memory Supply Deal
Nvidia Secures SK Hynix AI Memory Supply Deal
Goldman Sachs Backs Blockchain Real Estate Fund
Goldman Sachs Backs Blockchain Real Estate Fund
Keyrock to Buy Bankrupt Crypto Lender BlockFills for $3.25M
Keyrock to Buy Bankrupt Crypto Lender BlockFills for $3.25M
OKX Buys 19.6% of Coinone in $53M Korea Crypto Deal
OKX Buys 19.6% of Coinone in $53M Korea Crypto Deal
Compliance
New York Moves to Align Stablecoin Rules With GENIUS Act
New York Moves to Align Stablecoin Rules With GENIUS Act
Polymarket Faces Major Blow as South Korea Probes Users
Polymarket Faces Major Blow as South Korea Probes Users
FCA Flags Crypto Sponsorship Risks for Premier League Clubs
FCA Flags Crypto Sponsorship Risks for Premier League Clubs
Polymarket May Enforce KYC as Regulators Tighten Oversight
Polymarket May Enforce KYC as Regulators Tighten Oversight
CFTC and Gemini Ask Court to Undo $5M Settlement
CFTC and Gemini Ask Court to Undo $5M Settlement
Kenya Proposes New Crypto Taxes Under Finance Bill 2026
Kenya Proposes New Crypto Taxes Under Finance Bill 2026
Fintech
Bitget and xStocks Bring SpaceX IPO Access Onchain
Bitget and xStocks Bring SpaceX IPO Access Onchain
Bybit Launches IPO Express With Tokenized SpaceX Access
Bybit Launches IPO Express With Tokenized SpaceX Access
Pred Launches Sports Prediction Markets for FIFA World Cup
Pred Launches Sports Prediction Markets for FIFA World Cup
JPMorgan, Citi, BofA to Build Blockchain Deposit Network
JPMorgan, Citi, BofA to Build Blockchain Deposit Network
Moomoo Debuts Kalshi Powered Event Contracts for Retail Traders
Moomoo Debuts Kalshi Powered Event Contracts for Retail Traders
Shinhan Financial Joins Canton Network for Tokenized Assets
Shinhan Financial Joins Canton Network for Tokenized Assets
Finance
Bitmine Launches $300M Preferred Stock to Buy More ETH
Bitmine Launches $300M Preferred Stock to Buy More ETH
Coinbase Lists SpaceX Pre IPO Perpetual Futures
Coinbase Lists SpaceX Pre IPO Perpetual Futures
Binance Expands Into US Stocks With New bStocks Service
Binance Expands Into US Stocks With New bStocks Service
SEC Clears Paxos to Settle U.S. Stocks on Blockchain
SEC Clears Paxos to Settle U.S. Stocks on Blockchain
Mastercard Expands Stablecoin Strategy With NY BitLicense
Mastercard Expands Stablecoin Strategy With NY BitLicense
Russia Plans Full Exit of Visa and Mastercard From Market
Russia Plans Full Exit of Visa and Mastercard From Market
Newsletter Img

Too much noise in crypto?

We respect your time. You get one high-impact briefing a week. If the market is quiet, so are we.

✅ Join readers from Visa, Vanguard, and the FDIC.
Newsletter Img

The Weekly Briefing

We track the market 24/7. You get a 5-minute summary. If it’s quiet, we skip it.

✅ Read by pros at Visa, Vanguard, and the FDIC.