Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageDevSecOps Desk
DevSecOps

Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads

Six npm packages — three hijacked from legitimate projects — now use Ethereum smart contracts as a censorship-resistant channel to fetch malicious payloads, marking a practical evolution of blockchain-based C2 in supply-chain attacks.

Summary written by editorial AI · Source link below

Filed by Sonatype Blog1 min readRead at source ↗

TL;DR Sonatype Research Labs identified six npm packages delivering the same malicious payload: three hijacked legitimate packages and three additional malicious packages, tracked as sonatype-2026-005899 and sonatype-2026-005901 . The malware uses the same Ethereum wallet addr ess identified by OpenSourceMalware in a ctivity attributed to the DPRK-linked Contagious Interview campaign, using the "NullReceiver" technique to locate infrastructure hosting additional JavaScript payloads. Organization

Editorial Analysis

Why it matters

Blockchain-based command-and-control channels cannot be taken down via traditional domain seizures, forcing security teams to rethink how they detect and block supply-chain payload delivery.

What to do

Scan all npm dependency trees for the six identified packages and implement real-time SCA alerting for newly hijacked packages in your registries.

Board brief

Attackers are embedding malware distribution in blockchain infrastructure that cannot be seized or blocked by conventional means, raising the bar for software supply-chain defence.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Sonatype Blog

External link — opens at Sonatype Blog in a new tab.

§
Continue with

More from the DevSecOps Desk