New Malware Hiding Technique Targets Ethereum Smart Contracts

Hackers have developed a novel method to conceal malware within Ethereum smart contracts, posing a new challenge for security systems. ReversingLabs researchers discovered two malicious JavaScript packages, ‘colortoolsv2’ and ‘mimelib2’, recently added to the Node Package Manager (NPM). These packages function as downloaders, extracting command-and-control server addresses directly from blockchain data.