Thursday, October 30, 2025
No Result
View All Result
Crypto Waffle
  • Home
  • Bitcoin
  • Crypto Updates
    • General
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
Marketcap
  • Home
  • Bitcoin
  • Crypto Updates
    • General
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
No Result
View All Result
Crypto Waffle
No Result
View All Result

Hackers Use Ethereum Contracts to Hide Malware on NPM

September 5, 2025
in Crypto Updates
Reading Time: 2 mins read
0 0
A A
0
Home Crypto Updates
Share on FacebookShare on Twitter


Enjoyed this article?

Share it with your friends!

Hackers have discovered a new method for spreading malicious software by using Ethereum


ETH

$4,259.70

smart contracts to conceal crucial aspects of their attacks.

According to a blog post by Lucija Valentić at ReversingLabs, two suspicious software packages were found on the Node Package Manager (NPM), a platform used to share JavaScript code.

These packages, named “colortoolsv2” and “mimelib2”, were uploaded in July and designed to look like regular tools.

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

How to Use Crypto? 5 Rewarding Strategies Explained (Animated)

How to Use Crypto? 5 Rewarding Strategies Explained (Animated)
How to Use Crypto? 5 Rewarding Strategies Explained (Animated)

The packages acted like simple downloaders. When someone installed one, it would reach out to the Ethereum blockchain and fetch data from a smart contract. That data contained the location of a second piece of malware, which would then be downloaded and installed.

This made it hard for security systems to flag the packages as harmful, since they did not include any direct links to malicious websites or files.

Valentić explained that while Ethereum contracts have been misused before, this setup was different. In this case, the smart contract did not hold the malware itself, but held the location where it could be found.

The campaign was not limited to NPM. It also involved a fake open-source project hosted on GitHub. Hackers created a fake cryptocurrency trading bot, complete with fake updates, detailed documentation, and several user accounts to make the project seem active and trustworthy.

On September 1, SlowMist’s Yu Xian reported that attackers stole WLFI tokens from Ethereum wallets. How? Read the full story.



Source link

Tags: ContractsEthereumHackersHidemalwareNPM
Previous Post

SEC Briefed on Quantum Risk to Crypto Encryption Systems

Next Post

Bitcoin Price Watch: Bear Market Bounce or True Reversal? All Eyes on Volume

Related Posts

Crypto IPO Boom Fades: Only Circle and Galaxy Digital Show Profits, as eToro Drops 40%
Crypto Updates

Crypto IPO Boom Fades: Only Circle and Galaxy Digital Show Profits, as eToro Drops 40%

October 30, 2025
Bitcoin, Ether ETFs See Heavy Outflows While Solana Shines
Crypto Updates

Bitcoin, Ether ETFs See Heavy Outflows While Solana Shines

October 30, 2025
Live Trump Crypto Updates Today: Fed Cut Interest Rates as OFFICIAL TRUMP Surged 40%, and More…
Crypto Updates

Live Trump Crypto Updates Today: Fed Cut Interest Rates as OFFICIAL TRUMP Surged 40%, and More…

October 30, 2025
Behind the Vault Door: Tether Gold Attestation Report Reveals 375K Troy Ounces of Shine
Crypto Updates

Behind the Vault Door: Tether Gold Attestation Report Reveals 375K Troy Ounces of Shine

October 29, 2025
Ethereum’s Fusaka Upgrade Clears Final Test, Mainnet Next
Crypto Updates

Ethereum’s Fusaka Upgrade Clears Final Test, Mainnet Next

October 29, 2025
ASIC Confirms Stablecoins and Tokenised Assets Fall Under Financial Law
Crypto Updates

ASIC Confirms Stablecoins and Tokenised Assets Fall Under Financial Law

October 29, 2025
Next Post
Bitcoin Price Watch: Bear Market Bounce or True Reversal? All Eyes on Volume

Bitcoin Price Watch: Bear Market Bounce or True Reversal? All Eyes on Volume

Coinbase Pushes for AI-Native Workforce, Keeps Hiring

Coinbase Pushes for AI-Native Workforce, Keeps Hiring

These 3 Signals Statistically Predict Bitcoin’s Next Big Move

These 3 Signals Statistically Predict Bitcoin’s Next Big Move

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • USD
  • EUR
  • GBP
  • AUD
  • JPY
  • bitcoinBitcoin(BTC)
    $107,484.00
  • ethereumEthereum(ETH)
    $3,755.98
  • tetherTether(USDT)
    $1.00
  • binancecoinBNB(BNB)
    $1,063.90
  • rippleXRP(XRP)
    $2.42
  • solanaSolana(SOL)
    $182.28
  • usd-coinUSDC(USDC)
    $1.00
  • staked-etherLido Staked Ether(STETH)
    $3,756.92
  • tronTRON(TRX)
    $0.291040
  • dogecoinDogecoin(DOGE)
    $0.179545
Facebook Twitter Instagram Youtube RSS
Crypto Waffle

Your go-to source for the freshest cryptocurrency news, in-depth analysis, market trends, and expert insights.

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Web3

SITEMAP

  • About us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2025 Crypto Waffle.
Crypto Waffle is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Bitcoin
  • Crypto Updates
    • General
    • Altcoin
    • Ethereum
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis

Copyright © 2025 Crypto Waffle.
Crypto Waffle is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin(BTC)$107,484.00-3.57%
  • ethereumEthereum(ETH)$3,755.98-4.70%
  • tetherTether(USDT)$1.00-0.02%
  • binancecoinBNB(BNB)$1,063.90-4.83%
  • rippleXRP(XRP)$2.42-6.86%
  • solanaSolana(SOL)$182.28-6.79%
  • usd-coinUSDC(USDC)$1.000.00%
  • staked-etherLido Staked Ether(STETH)$3,756.92-4.66%
  • tronTRON(TRX)$0.291040-1.79%
  • dogecoinDogecoin(DOGE)$0.179545-8.21%

Powered by
...
►
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
►
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
►
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
►
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
►
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by