{"id":221393,"date":"2025-09-04T04:23:32","date_gmt":"2025-09-04T09:23:32","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2025\/09\/malicious-npm-packages-exploit-ethereum-smart-contracts-to-target-crypto-developers"},"modified":"2025-09-04T04:23:32","modified_gmt":"2025-09-04T09:23:32","slug":"malicious-npm-packages-exploit-ethereum-smart-contracts-to-target-crypto-developers","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2025\/09\/malicious-npm-packages-exploit-ethereum-smart-contracts-to-target-crypto-developers","title":{"rendered":"Malicious npm Packages Exploit Ethereum Smart Contracts to Target Crypto Developers"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/malicious-npm-packages-exploit-ethereum-smart-contracts-to-target-crypto-developers.jpg\"><\/a><\/p>\n<p>Cybersecurity researchers have discovered two new malicious packages on the npm registry that make use of smart contracts for the Ethereum blockchain to carry out malicious actions on compromised systems, signaling the trend of threat actors constantly on the lookout for new ways to distribute malware and fly under the radar.<\/p>\n<p>\u201cThe two npm packages abused smart contracts to conceal malicious commands that installed downloader malware on compromised systems,\u201d ReversingLabs researcher Lucija Valenti\u0107 <a href=\"https:\/\/www.reversinglabs.com\/blog\/ethereum-contracts-malicious-code\" rel=\"noopener\" target=\"_blank\">said<\/a> in a report shared with The Hacker News.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have discovered two new malicious packages on the npm registry that make use of smart contracts for the Ethereum blockchain to carry out malicious actions on compromised systems, signaling the trend of threat actors constantly on the lookout for new ways to distribute malware and fly under the radar. \u201cThe two npm packages [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3818,1761,34],"tags":[],"class_list":["post-221393","post","type-post","status-publish","format-standard","hentry","category-blockchains","category-cryptocurrencies","category-cybercrime-malcode"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/221393","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=221393"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/221393\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=221393"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=221393"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=221393"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}