Ethereum Smart Contracts Used in Malware Concealment: Hackers Target Developers

New findings from ReversingLabs reveal a sophisticated attack that exploited Ethereum’s smart contracts to inject malware into open-source software repositories like npm and GitHub. This tactic allows hackers to bypass traditional security measures and embed malicious code within developer projects, highlighting the evolving threat landscape in software supply chains. The incident, which occurred in July 2025, demonstrates how cybercriminals are adapting their techniques and exploiting vulnerabilities in the ever-growing ecosystem of open source software.