Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads

2026-08-10 Sonatype

https://www.sonatype.com/blog/six-npm-packages-use-ethereum-transactions-to-retrieve-malicious-payloads

Thumbnail for Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads

Six npm packages delivered an identical JavaScript loader, including three hijacked legitimate packages and three packages published with the malware already embedded. The loader used an Ethereum transaction as a dead drop, decoding command-and-control IP addresses from its recipient address before retrieving and executing additional payload stages. Sonatype linked the wallet and tradecraft to recent activity attributed to the DPRK-linked Contagious Interview campaign and the technique known as NullReceiver. Organizations that installed the affected versions should remove them and investigate for follow-on JavaScript execution or compromise.

Indicators of Compromise

Type Value First Seen Last Seen
WALLET 0xa322e5f3d311d3080e6f0121063e9… 2026-08-02 2026-08-10

Related Actors

Related Reports

« Back