Ethereum Smart Contracts Become Latest Hiding Spot For Malware

bitcoinist發佈於 2025-09-04更新於 2025-09-04

文章摘要

Reports have disclosed that hackers are taking advantage of Ethereum smart contracts to conceal malware commands, creating a fresh challenge...

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

Reports have disclosed that hackers are taking advantage of Ethereum smart contracts to conceal malware commands, creating a fresh challenge for cybersecurity teams.

Researchers say the method lets attackers hide behind blockchain traffic that often looks legitimate, making detection far more difficult.

New Attack Vector Surfaces

According to digital asset compliance firm ReversingLabs, two packages uploaded to the Node Package Manager (NPM) repository in July were found to use this method.

The packages, “colortoolsv2” and “mimelib2,” appeared harmless on the surface but contained hidden functions that pulled instructions from Ethereum smart contracts.

Figure 1: npm package colortoolsv2 being replaced with mimelib2. Source: ReversingLabs

Instead of directly hosting malicious links, they acted as downloaders, retrieving addresses for command-and-control servers before installing second-stage malware.

Lucija Valentić, a researcher at ReversingLabs, explained that what stood out was the hosting of malicious URLs on Ethereum contracts.

“That’s something we haven’t seen previously,” Valentić said, adding that it marks a quick shift in the way attackers are dodging security scans.

Figure 2: Malicious payload. Source: ReversingLabs

Fake Trading Bots And Social Tricks

The incident is not an isolated attempt. Researchers found that the packages were part of a much wider deception campaign, mainly carried out through GitHub.

Hackers had built fake cryptocurrency trading bot repositories, filling them with fabricated commits, multiple fake maintainer accounts, and polished documentation to lure developers. These projects were designed to look trustworthy, hiding the real purpose of delivering malware.

In 2024 alone, 23 crypto-related malicious campaigns were documented across open-source repositories. Security analysts believe this latest tactic, combining blockchain commands with social engineering, raises the bar for anyone trying to defend against such attacks.

ETHUSD trading at $4,375 on the 24-hour chart: TradingView

Past Cases Targeting Crypto Projects

Ethereum is not the only blockchain pulled into these schemes. Earlier this year, the North Korean-linked Lazarus Group was tied to malware that also touched Ethereum contracts, though the approach then was different.

In April, attackers spread a fake GitHub repository posing as a Solana trading bot, using it to plant malware that stole wallet credentials.

Another case involved “Bitcoinlib,” a Python library meant for Bitcoin development, which hackers targeted for similar purposes.

While the specific methods shift, the trend is clear: crypto-related developer tools and open-source code repositories are being used as traps. The use of blockchain features such as smart contracts is only making the problem harder to detect.

Valentić summed it up by saying that attackers are constantly searching for fresh ways to bypass defenses. Hosting malicious commands on Ethereum contracts, she said, shows how far some are willing to go to stay one step ahead.

Featured image from Meta, chart from TradingView

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Christian, a journalist and editor with leadership roles in Philippine and Canadian media, is fueled by his love for writing and cryptocurrency. Off-screen, he's a cook and cinephile who's constantly intrigued by the size of the universe.

你可能也喜歡

对话42 Macro创始人:美联储的“温水煮青蛙”与K型经济

来源:Anthony Pompliano,整理:Felix, PANews 42 Macro创始人Darius Dale近日参与访谈,探讨了美联储政策、K型经济与投资策略。他认为新任美联储主席凯文·沃什实质是“披着鹰派外衣的鸽派”,未来可能先通过收紧政策或鹰派信号为后续宽松创造空间。Dale指出,当前通胀驱动因素(如货币供应、赤字支出、信贷增长)均显示通胀难以回到2%目标,美联储已“放弃”这一目标,其角色如同“温水煮青蛙”,在金融抑制中缓慢稀释货币购买力。 他强调美国经济呈现显著的“K型”分化:顶部家庭因疫情期间积累约8万亿美元超额储蓄,消费强劲、财富增长;而底层家庭却面临信用卡、车贷等重度违约率升至金融危机水平,生活艰难。这种分化加剧了社会不平等与政治焦虑,根源在于货币增发带来的“坎蒂隆效应”——新钱优先流入富人与资产市场,推高资产价格,而工薪阶层承受物价上涨。 谈及市场,Dale认为投资者必须参与资产配置以抵御财富稀释,但AI热潮下的“科技七巨头”可能面临过度投资与资本开支激增的风险,资金或流向更广泛的股票。他最后指出,不同族裔的底层民众诉求本质相同:尊严与养家能力,当前经济机制若持续加剧分化,可能引发严重社会后果。

marsbit2 小時前

对话42 Macro创始人:美联储的“温水煮青蛙”与K型经济

marsbit2 小時前

交易

現貨
活动图片