Trade Haven Hub - Investing and Stock News
  • Investment Tips
  • Trade Tips
  • Crypto News
  • Economy News
  • Stock Market
  • Investment Tips
  • Trade Tips
  • Crypto News
  • Economy News
  • Stock Market
No Result
View All Result
Trade Haven Hub - Investing and Stock News
No Result
View All Result
Home Crypto News

Hackers Exploit Ethereum to Inject Malware in Popular Coding Libraries

by
September 4, 2025
in Crypto News
0
Hackers Exploit Ethereum to Inject Malware in Popular Coding Libraries
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Hackers are now exploiting vulnerabilities in widely-used NPM coding libraries to inject malware into Ethereum smart contracts, according to cybersecurity research by blockchain compliance firm Reversing Labs(RL).

In a September 3 blog post detailing the discovery, researcher Lucija Valentić revealed that threat actors bypass security scans by exploiting new open-source malware present in the Node Package Manager (NPM) package repository, which contains extensive JavaScript packages and libraries.

The most destructive malware discovered was “colortoolsv2” and “mimelib2“, both published in July, which were found to abuse smart contracts to conceal malicious commands that install downloader malware on infected systems.

Source: ReversingLabs

How Ethereum Smart Contracts Turn Into Malware Command Centers

These packages are part of broader open-source libraries affecting both NPM and GitHub, where malicious supply chain actors use advanced social engineering and deception tactics to trick developers into incorporating harmful code into their projects.

According to ReversingLabs, 2025 has witnessed a diverse range of malicious campaigns targeting NPM, the leading online repository for JavaScript packages.

In March, RL documented the discovery of NPM packages ethers-provider2 and ethers-providerz

Since discovering the ethers campaign, researchers have detected numerous additional infostealers, downloaders, and droppers found on NPM.

At the beginning of July, RL researcher Karlo Zanki discovered and reported a new NPM campaign involving a basic package that deployed blockchain in a novel way to deliver a malicious second stage.

RL threat researchers detected a malicious #npm package abusing #blockchain for malicious command hosting: https://t.co/Hc0QjaH3So pic.twitter.com/uQ3xXAIEkZ

— ReversingLabs (@ReversingLabs) July 11, 2025

The exact package colortoolsv2 is being used to infiltrate Ethereum smart contracts.

According to RL researchers, the malware is a basic NPM package containing just two files.

The major file is a script named index.js, which contains a hidden malicious payload.

Once installed in a project, the script would run to fetch blockchain data and execute a harmful command by loading the URL for a command and control (C2) server that would then download second-stage malware to the requesting system.

Although “downloader” malware is a common method hackers use in NPM repositories to target victims, this specific malware is unusual as it uses Ethereum smart contracts to host the URLs where malicious commands are located for downloading the second-stage malware.

It gets even more fancy: the way Etherscan was tricked showing the wrong implementation contract is based on setting 2 different proxy slots in the same frontrunning tx. So Etherscan uses a certain heuristic that incorporates different storage slots to retrieve the implementation… https://t.co/8VSCKK7DfY pic.twitter.com/OyxcxZwg5N

— sudo rm -rf –no-preserve-root / (@pcaversaccio) July 10, 2025

Notably, the cybersecurity researchers acknowledge that they haven’t encountered this approach previously.

Two-File Malware Hides a $2.5M Bridge Exploit Method

The researchers uncovered a Solana-trading-bot infected by the malicious colortoolsv2 package called solana-trading-bot-v2, which appears to be a trustworthy GitHub project to the average observer.

Source: ReversingLabs

It has thousands of commits, several active contributors, and a decent number of stars and watchers, all characteristics of legitimate open-source repositories.

However, all these details were fabricated, and any developer who installs it risks having user wallets that interact with the bot drained of funds.

Software supply chain attacks targeting smart contracts and blockchain infrastructure are now on the rise.

In July, hackers exploited a vulnerability in Arcadia Finance’s Rebalancer contract, draining approximately $2.5 million in cryptocurrency from the decentralized finance platform operating on Base blockchain.

The attackers manipulated arbitrary swapData parameters to execute unauthorized swaps that emptied user vaults.

A recent report by blockchain analytics firm Global Ledger revealed that hackers have now stolen $3 billion worth of crypto in 119 separate incidents during the first half of 2025, which is 150% more than all of 2024.

Slava Demchuk, CEO of analytics firm AMLBot, said access-control flaws and smart contract vulnerabilities, especially in bridges, continue to be dominant attack methods.

Demchuk told Cryptonews that these hackers are exploiting the interconnected and composable nature of decentralized finance (DeFi) protocols to amplify the impact.

Blockchain auditors advised that it is critical for developers to assess each library they are considering implementing before deciding to include it in their development cycle.

The post Hackers Exploit Ethereum to Inject Malware in Popular Coding Libraries appeared first on Cryptonews.

Previous Post

BAY Miner Launches Mobile App: Your Phone as a ‘Mining Terminal’ for BTC/ETH/XRP

Next Post

XRP Price Prediction: Target $10 Amid ETF Approval and Rate Cut Warnings, FindMining Officially Launches XRP-Based Mobile App

Next Post
XRP Price Prediction: Target $10 Amid ETF Approval and Rate Cut Warnings, FindMining Officially Launches XRP-Based Mobile App

XRP Price Prediction: Target $10 Amid ETF Approval and Rate Cut Warnings, FindMining Officially Launches XRP-Based Mobile App

  • Trending
  • Comments
  • Latest
Buy Bitcoin Under $100K Before The Next Bull Run

Buy Bitcoin Under $100K Before The Next Bull Run

April 22, 2025
Quantum Computing: its Evolution and its Potential Future

Quantum Computing: its Evolution and its Potential Future

March 20, 2025
Stock Market News UK Update: FTSE 100 & 250 Rise

Stock Market News UK Update: FTSE 100 & 250 Rise

March 20, 2025
Oil Prices Rebound After Trump’s Criticism of Powell

Oil Prices Rebound After Trump’s Criticism of Powell

April 22, 2025
India to Roll Out Sovereign RBI-Backed Digital Currency, Minister Flags Unbacked Crypto

India to Roll Out Sovereign RBI-Backed Digital Currency, Minister Flags Unbacked Crypto

0
Quantum Computing: its Evolution and its Potential Future

Quantum Computing: its Evolution and its Potential Future

0
Quantum Computing: its Evolution and its Potential Future

Quantum Computing: its Evolution and its Potential Future

0
Air Direct Capture – Reducing CO2 from the Atmosphere

Air Direct Capture – Reducing CO2 from the Atmosphere

0
India to Roll Out Sovereign RBI-Backed Digital Currency, Minister Flags Unbacked Crypto

India to Roll Out Sovereign RBI-Backed Digital Currency, Minister Flags Unbacked Crypto

October 7, 2025
[LIVE] Crypto News Today: Latest Updates for Oct. 07, 2025 – Bitcoin Hits All-Time High Above $126K Amid Political Stalemate, $150K in Sight

[LIVE] Crypto News Today: Latest Updates for Oct. 07, 2025 – Bitcoin Hits All-Time High Above $126K Amid Political Stalemate, $150K in Sight

October 7, 2025
Bitcoin Sets New Record High Above $126K As Political Gridlock Boosts Haven Assets

Bitcoin Sets New Record High Above $126K As Political Gridlock Boosts Haven Assets

October 7, 2025
Hawley rips Jack Smith’s ‘Biden’s Stasi’ probe, calls alleged spying ‘abuse of power beyond Watergate’

Hawley rips Jack Smith’s ‘Biden’s Stasi’ probe, calls alleged spying ‘abuse of power beyond Watergate’

October 7, 2025

    Stay updated with the latest news, exclusive offers, and special promotions. Sign up now and be the first to know! As a member, you'll receive curated content, insider tips, and invitations to exclusive events. Don't miss out on being part of something special.


    By opting in you agree to receive emails from us and our affiliates. Your information is secure and your privacy is protected.

    Recent News

    India to Roll Out Sovereign RBI-Backed Digital Currency, Minister Flags Unbacked Crypto

    India to Roll Out Sovereign RBI-Backed Digital Currency, Minister Flags Unbacked Crypto

    October 7, 2025
    [LIVE] Crypto News Today: Latest Updates for Oct. 07, 2025 – Bitcoin Hits All-Time High Above $126K Amid Political Stalemate, $150K in Sight

    [LIVE] Crypto News Today: Latest Updates for Oct. 07, 2025 – Bitcoin Hits All-Time High Above $126K Amid Political Stalemate, $150K in Sight

    October 7, 2025
    Bitcoin Sets New Record High Above $126K As Political Gridlock Boosts Haven Assets

    Bitcoin Sets New Record High Above $126K As Political Gridlock Boosts Haven Assets

    October 7, 2025
    Hawley rips Jack Smith’s ‘Biden’s Stasi’ probe, calls alleged spying ‘abuse of power beyond Watergate’

    Hawley rips Jack Smith’s ‘Biden’s Stasi’ probe, calls alleged spying ‘abuse of power beyond Watergate’

    October 7, 2025
    • About us
    • Contact us
    • Privacy Policy
    • Terms & Conditions

    Copyright © 2025 tradehavenhub.com | All Rights Reserved

    No Result
    View All Result
    • Investment Tips
    • Trade Tips
    • Crypto News
    • Economy News
    • Stock Market

    Copyright © 2025 tradehavenhub.com | All Rights Reserved