Cybercriminals Exploit Smart Contracts to Conceal Malicious NPM Packages

New research reveals cybercriminals are using a clever tactic to infiltrate the open-source ecosystem, compromising software security. Instead of directly embedding malicious code in npm packages, these attackers use Ethereum smart contracts to conceal commands and redirect users to harmful downloads. This sophisticated strategy aims to evade detection by traditional security tools, making it difficult for developers and organizations to identify and eliminate threats.