
Malicious npm Packages Exploit Ethereum Wallet to Conceal C2 Infrastructure
CybersecuritySupplyChainAttacksBlockchainExploitsMalware
Six malicious npm packages were identified querying an Ethereum wallet address to retrieve command-and-control (C2) server infrastructure details. The packages exploited blockchain transactions to dynamically fetch C2 addresses, evading static detection methods. No specific dates, affected versions, or CVE identifiers were disclosed in the report. The attack targeted the npm ecosystem, a widely used JavaScript package registry. The technique allowed threat actors to conceal malicious infrastructure by leveraging decentralized blockchain data. The impact included potential supply chain compromise for developers incorporating these packages.