Close Menu
AsiaTokenFundAsiaTokenFund
  • Home
  • Crypto News
    • Bitcoin
    • Altcoin
  • Web3
    • Blockchain
  • Trading
  • Regulations
    • Scams
  • Submit Article
  • Contact Us
  • Terms of Use
    • Privacy Policy
    • DMCA
What's Hot

Bitcoin Price And Ethereum Both Struggle As Analysts Highlight Remittix As The Best Crypto Buy For 2025

September 4, 2025

XRP Price Today Holds Near $2.82 While Traders Call Remittix The Best PayFi Altcoin To Watch

September 4, 2025

Ondo Brings 100+ Tokenized U.S. Stocks and ETFs to Global Investors

September 4, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) YouTube LinkedIn
AsiaTokenFundAsiaTokenFund
ATF Capital
  • Home
  • Crypto News
    • Bitcoin
    • Altcoin
  • Web3
    • Blockchain
  • Trading
  • Regulations
    • Scams
  • Submit Article
  • Contact Us
  • Terms of Use
    • Privacy Policy
    • DMCA
AsiaTokenFundAsiaTokenFund

Ethereum Smart Contracts Misused As Tools For Hiding Malware

0
By on September 4, 2025 Altcoin, Bitcoin, Regulations, Trading, Web3
Share
Facebook Twitter LinkedIn Pinterest Email

The post Ethereum Smart Contracts Misused As Tools For Hiding Malware appeared first on Coinpedia Fintech News

Ethereum, the backbone of crypto apps and DeFi projects, is increasingly being used as a tool for cyberattacks.

Researchers at ReversingLabs have found two npm packages that hid malicious commands inside Ethereum smart contracts, marking a new twist in software supply chain attacks.

Read on to know how this was carried out.

Simple Packages With Hidden Malwares

The two packages, colortoolsv2 and mimelib2, looked like harmless tools, but they secretly pulled in downloader malware. These packages are part of a broader, sophisticated campaign spreading across npm and GitHub.

In July, RL discovered colortoolsv2 using blockchain to deliver malware. It was quickly removed, but a near-identical package called mimelib2 soon appeared with the same malicious code. 

Both npm packages were minimal and carried only the malware, while their GitHub repositories were made to look polished and reliable to fool developers.

Using Smart Contracts as a Stealth Tool

What makes this campaign stand out is how the attackers used Ethereum smart contracts to hide malicious URLs.

Colortoolsv2 appeared to be a basic npm package with only two files. Hidden inside was a script that downloaded additional malware from a command-and-control server. Usually, malware campaigns hardcode URLs into their code, which makes them easier to detect. 

In this case, the URLs were stored inside Ethereum smart contracts, making it much harder to track and shut down the attack.

“That’s something we haven’t seen previously, and it highlights the fast evolution of detection evasion strategies by malicious actors who are trolling open source repositories and developers,” the researchers said. 

Hackers Are Getting More Creative 

This attack is part of a growing trend where hackers are finding new ways to deliver malware. In 2023, some Python packages hid malicious URLs inside GitHub Gists, and in 2022, a fake Tailwind CSS npm package stored malware links behind trusted platforms like Google Drive and OneDrive.

How GitHub Was Used as Trap

The attackers also built fake GitHub repositories to make their campaign more convincing.

Attackers set up fake repositories tied to the colortoolsv2 package, posing as crypto trading bots. These projects looked convincing, with thousands of commits, active contributors, and plenty of stars. 

But the activity and popularity were faked to trick developers into downloading poisoned code.

This campaign didn’t stop with solana-trading-bot-v2. Other repos like ethereum-mev-bot-v2, arbitrage-bot, and hyperliquid-trading-bot also showed fake commits and activity, though less convincing.

Last year saw 23 campaigns where attackers planted malicious code in open-source repos, including the ultralytics PyPI crypto miner and an April 2025 malware attempt on local crypto tools. 

For developers, this is a reminder to carefully vet open-source libraries. Stars, downloads, and activity do not guarantee trust. Both code and maintainers need to be thoroughly reviewed before integration.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Bitcoin Price And Ethereum Both Struggle As Analysts Highlight Remittix As The Best Crypto Buy For 2025

September 4, 2025

XRP Price Today Holds Near $2.82 While Traders Call Remittix The Best PayFi Altcoin To Watch

September 4, 2025

Ondo Brings 100+ Tokenized U.S. Stocks and ETFs to Global Investors

September 4, 2025
Leave A Reply Cancel Reply

What's New Here!

Bitcoin Price And Ethereum Both Struggle As Analysts Highlight Remittix As The Best Crypto Buy For 2025

September 4, 2025

XRP Price Today Holds Near $2.82 While Traders Call Remittix The Best PayFi Altcoin To Watch

September 4, 2025

Ondo Brings 100+ Tokenized U.S. Stocks and ETFs to Global Investors

September 4, 2025

Meme Giants PEPE, DOGE, SHIB Stumble – Analysts Call Layer Brett the Top Meme Coin Buy Now

September 4, 2025
AsiaTokenFund
Facebook X (Twitter) LinkedIn YouTube
  • Home
  • Crypto News
    • Bitcoin
    • Altcoin
  • Web3
    • Blockchain
  • Trading
  • Regulations
    • Scams
  • Submit Article
  • Contact Us
  • Terms of Use
    • Privacy Policy
    • DMCA
© 2025 asiatokenfund.com - All Rights Reserved!

Type above and press Enter to search. Press Esc to cancel.

Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.