Researchers have discovered that hackers are using Ethereum smart contracts to hide malicious code, marking a sophisticated evolution in supply chain attacks.
A new report from ReversingLabs shows that hackers are exploiting the Ethereum blockchain as a covert communication channel to deploy malware, marking a sophisticated evolution in supply chain attacks.
Researchers discovered two malicious packages in the Node Package Manager (NPM) repository, named “colortoolsv2” and “mimelib2,” released in July. Instead of embedding malicious links directly into the source code — which is easy for scanners to detect — the packages act as loaders.

Once installed, they send a query to an Ethereum smart contract, which returns the control server address to download the second-stage payload. The initial traffic thus appears legitimate, making detection nearly impossible.
What’s new, according to researcher Lucija Valentić, is the use of an Ethereum smart contract to host the URL containing the malicious command — a variation on previous tactics. This shows the rapid evolution of supply chain attacks, as hackers continue to exploit emerging technologies to bypass traditional defenses.
The threat doesn’t stop there. The malicious packages are just one part of a larger scam: hackers have set up fake code repositories on GitHub, masquerading as crypto-asset trading bot projects. These repositories are elaborately prepared with fake commit histories, fake tracking accounts, and professionally written technical documentation, all designed to fool unsuspecting developers.
The emergence of this technique reflects an alarming trend: in 2024 alone, researchers recorded at least 23 crypto-asset-related malware campaigns on open source repositories. In addition to Ethereum, similar attacks have also targeted the Solana ecosystem and the popular Python library “Bitcoinlib,” indicating a growing threat.
About BingX Founded in 2018, BingX is one of the leading cryptocurrency exchanges with over 20 million users worldwide. BingX offers a variety of products and services such as: Spot trading, Futures Contract, copy trading, etc. to meet the needs of users of all levels. In addition, BingX exchange is proud to be the official partner of Chelsea FC. Download BingX Exchange app on iOS or Android now to start your investment journey! |