• Send Us A Tip
  • Calling all Tech Writers
  • Advertise
Sunday, June 21, 2026
  • Login
TechStory
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
TechStory
No Result
View All Result
Home Crypto

Hackers Leverage Blockchain to Conceal Malware in Plain Sight

by Anindya Paul
September 4, 2025
in Crypto, Ethereum
Reading Time: 3 mins read
0
Ethereum

Source: holder.io

TwitterWhatsappLinkedin

A new advanced malware campaign has been discovered, and cybercriminals have developed a novel and creative way to evade traditional security measures. Researchers from ReversingLabs found that threat actors are utilizing Ethereum smart contracts to obfuscate malicious URLs, a method that will make their code durable and extremely hard to detect. This revelation represents a dramatic evolution in the war against software supply chain attacks.

You might also like

How Bitcoin ETF Taxes Work: A Complete Guide for Investors

How to Reduce Crypto Taxes Legally: Smart Strategies Every Cryptocurrency Investor Should Know

The Battle of the Stablecoins: A Comprehensive Guide to USDT vs USDC

The Hidden Threat in Your Code

Typically, malicious software packages contain suspicious URLs or scripts within their own files, which security scanners are designed to flag. However, in this latest attack, the hackers took a different route. They used two npm packages, “colortoolv2” and “mimelib2,” which only served as “dumb downloaders.” Rather than embedding the malicious code directly, these packages contained instructions to call an Ethereum smart contract after installation and get the location of the next stage of malware. This creative approach allows the malicious activity to be hidden in the public, decentralized ledger of the Ethereum blockchain, making it almost impossible to remove and difficult to trace.

A Fabricated World of Legitimacy

The packages were not distributed at random. ReversingLabs’ investigation revealed they were part of a larger deception campaign on GitHub. The malicious npm packages were concealed in repositories masquerading as legitimate cryptocurrency trading bots with names like ‘solana-trading-bot-v2’ and ‘hyperliquid-trading-bot-v2.’ In order to confer some legitimacy on the repositories, attackers established a coordinated network of fake accounts to have a trusted relationship based on metrics such as stars and commits.

This network has been established as linked to a group called ‘Stargazer’s Ghost Network.’ The total web of accounts inadvertently inflated the apparent credibility of the repositories. These accounts created fake commits and stars while making accounts appear to represent legitimate maintainers to pretend that the project had some level of interest or community. This type of social engineering was primarily targeted at developers who are searching for open-source cryptocurrency tools and would mistake such activity for community support.

The Elusive Nature of the Threat

The attackers had a multi-tiered approach to avoid detection. When one of their payloads, “colortoolv2,” was detected and taken down, the attackers provided another package that was functionally identical, (the attacker’s payload decided to call it “mimelib2”). The attackers were able to continue their attack campaign with hardly any disruptions. The use of a public blockchain for their command and control infrastructure is also smart, as the command and control addresses are stored in immutable ledger that cannot be taken down, but only updated by the attackers which results in a robust and resilient C2 framework.

Evolving Tactics in a Growing Threat Landscape

This recent finding is part of a greater trend of more serious software supply chain attacks and noted that there were 23 incidents related to the software supply chain in the cryptocurrency space in 2024 alone. All of these attacks demonstrated the ability of cybercriminals to find new ways to exploit trusted applications. Past incidents have included using trusted services like Google Drive and GitHub Gist to mask malicious C2 servers, and compromising other well-known packages on registries like PyPI.

A Call for Increased Vigilance

The findings emphasize that there must be caution with using an open-source library in your development work. Developers cannot rely on the formula of traditional, socially accepted indicators of a package’s legitimacy such as the amount of stars a package has or the amount of commits. Experts agree that developers need to be cautious and analyze any library or package before using it. As our threat envelope expands, so too must our approach to security. This new iteration of blockchain technology highlights that threat actors are becoming increasingly elusive and clever, and is a stark reminder that these days, due diligence is more important than ever.

Tweet55SendShare15
Previous Post

BYD Cuts 2025 Sales Target Amid Cooling Demand and Fierce Competition

Next Post

SEC Shifts Course Toward a Crypto-Friendly Future

Anindya Paul

Professional content creator with strong expertise in content writing, filmmaking and social media strategy. Skilled in digital storytelling, scriptwriting, video production, sound design and graphic design - crafting compelling narratives across platforms. Known for delivering high-quality, engaging content under tight deadlines. A collaborative team player with a sharp creative instinct, adaptability to evolving trends, and a focus on impactful, results-driven communication.

Recommended For You

How Bitcoin ETF Taxes Work: A Complete Guide for Investors

by Anindya Paul
June 21, 2026
0
Bitcoin ETF

The issuance of Bitcoin exchange-traded funds (ETFs) has boosted investor confidence in cryptocurrency investments. Now, rather than physically owning and storing their investments through digital currency exchanges or...

Read more

How to Reduce Crypto Taxes Legally: Smart Strategies Every Cryptocurrency Investor Should Know

by Anindya Paul
June 21, 2026
0
Taxes

As time goes on, crypto-currency continues its evolution from a niche technological experiment to the newest global investment asset class worth trillions of dollars, with millions of investors...

Read more

The Battle of the Stablecoins: A Comprehensive Guide to USDT vs USDC

by Anindya Paul
June 19, 2026
0
USDC vs USDT

The world of cryptocurrency is well known for its extreme volatility; price can drop or increase by double digits within just a few minutes. For investors trying to...

Read more
Next Post
SEC

SEC Shifts Course Toward a Crypto-Friendly Future

Please login to join discussion

Techstory

Tech and Business News from around the world. Follow along for latest in the world of Tech, AI, Crypto, EVs, Business Personalities and more.
reach us at info@techstory.in

Advertise With Us

Reach out at - info@techstory.in

Aviator Game India 2026

BROWSE BY TAG

#Crypto #howto 2024 acquisition AI amazon Apple Artificial Intelligence bitcoin Business China cryptocurrency e-commerce electric vehicles Elon Musk Ethereum facebook funding Gaming Google India Instagram Investment ios iPhone IPO Market Markets Meta Microsoft News OpenAI samsung Social Media SpaceX startup startups tech technology Tesla TikTok trend trending twitter US

© 2025 Techstory.in

No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to

© 2025 Techstory.in

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?