DeFi Daily News
Thursday, October 23, 2025
Advertisement
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
No Result
View All Result
Home DeFi Web 3

rewrite this title Hackers Using Ethereum Smart Contracts to Deliver Malware: Report – Decrypt

Ryan Gladwin by Ryan Gladwin
September 4, 2025
in Web 3
0 0
0
rewrite this title Hackers Using Ethereum Smart Contracts to Deliver Malware: Report – Decrypt
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Telegram
Listen to this article


rewrite this content using a minimum of 1000 words and keep HTML tags

In brief

Public code libraries are being poisoned with malware that is being downloaded via Ethereum smart contracts.
Software security firm ReversingLabs identified a sophisticated network of malicious packages using this method with fake activity to give a sense of legitimacy.
Binance chief security officer, Jimmy Su, told Decrypt in August that package poisoning like this is one of the main vectors of attack that North Korean hackers use.

Software security firm ReversingLabs has identified two open-source code packages that use Ethereum smart contracts to download malware. It forms part of a “sophisticated campaign” of malicious actors attempting to hack users via poisoned blockchain-related public code libraries—a vector of attack Binance has previously linked to North Korean hackers.

The two Node Package Manager (NPM) libraries, or packages, called colortoolsv2 and mimelib2, were effectively identical in that they contained two files, one of which would run a script that downloads the second half of the malware attack via an Ethereum smart contract. NPM packages are collections of reusable, open-source code that developers will frequently use.

Lucija Valentić, Software threat researcher at ReversingLabs, wrote that the use of smart contracts was “something we haven’t seen previously.” 

“‘Downloaders’ that retrieve late-stage malware are being published to the npm repository weekly—if not daily,” she said. “What is new and different is the use of Ethereum smart contracts to host the URLs where malicious commands are located, downloading the second-stage malware.”

These two packages were just the tip of the iceberg, as ReversingLabs found a larger campaign of poisoned packages across GitHub. The security firm discovered a network of GitHub repositories that were connected to the aforementioned malicious package colortoolsv2. Most of the network was branded as crypto trading bots or token sniping tools.

“Even though the NPM package wasn’t very sophisticated, there was much more work put into making the repositories holding the malicious package look trustworthy,” Valentić said. 

She explained in the report that some repositories had thousands of commits, a good number of stars, and a couple of contributors, which could lead a developer to trust it. But ReversingLabs believes that most of this activity was faked by the attackers.

“It is especially dangerous because programmers wouldn’t think it’d be an issue when they use publicly maintained codebases,” 0xToolman, a pseudonymous on-chain sleuth at Bubblemaps, told Decrypt. “It could be the assumption that open source equals public monitoring equals safety. It could be simply that one is unable to check every code he is using as he did not write it, and it would take so much time to do so.”

Binance links NPM poisoning to DPRK

Major centralized exchange Binance told Decrypt last month that it was aware of such attacks and forces employees to go through NPM libraries with a fine-tooth comb as a result. 

Binance chief security officer, Jimmy Su, explained that package poisoning is a growing vector of attack for North Korean hackers, which he identified as the single biggest threat to crypto companies.

“The largest vector currently against the crypto industry is state actors, particularly in the DPRK, [with] Lazarus,” Su told Decrypt in August. “They’ve had a crypto focus in the last two, three years and have been quite successful in their endeavors.”

North Korean hackers are believed to have been responsible for 61% of all crypto stolen in 2024, a Chainalysis report revealed, which totalled $1.3 billion. Since then, the FBI has attributed North Korean attackers to the $1.4 billion Bybit hack, which is the largest crypto hack of all time.

While the main vector of attack that Su has noted is via fake employees, NPM package poisoning is in second place alongside fake interview scams. As such, major crypto exchanges share intelligence via Telegram and Signal groups so they can highlight poisoned libraries.

“We are mostly in this alliance on the frontline, so for the first responders, when [there are] hacks or [we need] incident response. We are always in this group, like with other exchanges, such as Coinbase, Kraken,” Su explained. “We’ve been in alliance with those exchanges for years now. There are more formal ones that are being formed today, but in terms of operating on the frontline. We’ve been doing that for years now.”

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

and include conclusion section that’s entertaining to read. do not include the title. Add a hyperlink to this website http://defi-daily.com and label it “DeFi Daily News” for more trending news articles like this



Source link

Tags: contractsDecryptDeliverEthereumHackersmalwarereportrewriteSmarttitle
ShareTweetShare
Previous Post

Federal Reserve Needs to Help the US Solve Its Debt Problem, Wilson Says

Next Post

US Economy: Jobless Claims Rise, Trade Gap Widens

Next Post
US Economy: Jobless Claims Rise, Trade Gap Widens

US Economy: Jobless Claims Rise, Trade Gap Widens

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
  • Trending
  • Comments
  • Latest
Why Outlet Malls Are Struggling In The U.S.

Why Outlet Malls Are Struggling In The U.S.

July 16, 2024
rewrite this title Soulframe Joineries and reforging guide

rewrite this title Soulframe Joineries and reforging guide

July 28, 2025
Live Coverage of Triathlon Decision at Olympics 2024 as Beth Potter and Alex Yee Compete for Gold

Live Coverage of Triathlon Decision at Olympics 2024 as Beth Potter and Alex Yee Compete for Gold

July 31, 2024
rewrite this title Repair from Millions of Kilometers Away: How NASA Keeps the Mars Rovers Alive

rewrite this title Repair from Millions of Kilometers Away: How NASA Keeps the Mars Rovers Alive

September 29, 2025
Use rhino.fi to make payments with cryptocurrency and maintain your anonymity

Use rhino.fi to make payments with cryptocurrency and maintain your anonymity

August 14, 2024
rewrite this title Berkshire Hathaway to buy Occidental’s OxyChem for .7 billion, in Buffett’s biggest deal in three years

rewrite this title Berkshire Hathaway to buy Occidental’s OxyChem for $9.7 billion, in Buffett’s biggest deal in three years

October 2, 2025
rewrite this title and make it good for SEOAvihai Stolero, Themis buy mineral water co Mey Eden

rewrite this title and make it good for SEOAvihai Stolero, Themis buy mineral water co Mey Eden

October 23, 2025
rewrite this title Eedi AI Review – The Intelligent Tutoring Platform Revolutionizing Online Learning – Metaverse Planet

rewrite this title Eedi AI Review – The Intelligent Tutoring Platform Revolutionizing Online Learning – Metaverse Planet

October 23, 2025
rewrite this title Ethereum Market Outlook: ,100 Resistance Holds as BlackRock and Major Funds Boost Exposure | Bitcoinist.com

rewrite this title Ethereum Market Outlook: $4,100 Resistance Holds as BlackRock and Major Funds Boost Exposure | Bitcoinist.com

October 23, 2025
rewrite this title Paxos Co-Founder Calls ‘Transparency’ a Silver Lining Following 0T Stablecoin Snafu – Decrypt

rewrite this title Paxos Co-Founder Calls ‘Transparency’ a Silver Lining Following $300T Stablecoin Snafu – Decrypt

October 23, 2025
rewrite this title with good SEO Ethereum Slides Gradually — Buyers Losing Control As Market Turns Cautious

rewrite this title with good SEO Ethereum Slides Gradually — Buyers Losing Control As Market Turns Cautious

October 23, 2025
rewrite this title UK AI Company Wonder Studios Raises M From Investors Including Atomico & Adobe

rewrite this title UK AI Company Wonder Studios Raises $12M From Investors Including Atomico & Adobe

October 23, 2025
DeFi Daily

Stay updated with DeFi Daily, your trusted source for the latest news, insights, and analysis in finance and cryptocurrency. Explore breaking news, expert analysis, market data, and educational resources to navigate the world of decentralized finance.

  • About Us
  • Blogs
  • DeFi-IRA | Learn More.
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.