TechFlow news, September 4 — According to The Block, a recent report by security firm ReversingLabs reveals hackers are employing innovative methods to hide malicious instructions within npm packages by leveraging Ethereum smart contracts. Two malicious packages named "colortoolsv2" and "mimelib2" emerged in July this year, retrieving commands for the next attack phase through queries to Ethereum contracts instead of hardcoding URLs directly into the code, significantly increasing detection and removal difficulty.
The attackers also created fake cryptocurrency-themed GitHub repositories, boosting their credibility with forged stars and auto-generated commit histories to trick developers into adding these dependencies.




