Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads
2026-08-10 • Sonatype •
Six npm packages delivered an identical JavaScript loader, including three hijacked legitimate packages and three packages published with the malware already embedded. The loader used an Ethereum transaction as a dead drop, decoding command-and-control IP addresses from its recipient address before retrieving and executing additional payload stages. Sonatype linked the wallet and tradecraft to recent activity attributed to the DPRK-linked Contagious Interview campaign and the technique known as NullReceiver. Organizations that installed the affected versions should remove them and investigate for follow-on JavaScript execution or compromise.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| WALLET | 0xa322e5f3d311d3080e6f0121063e9… | 2026-08-02 | 2026-08-10 |