Malicious npm Package Used Ethereum Smart Contract to Hide C2 Infrastructure
Security firm Checkmarx discovered that a malicious npm package called indexed-btree, mimicking the legitimate sorted-btree library, had accumulated nearly 2 million weekly downloads before being identified as malware. Unlike typical supply chain attacks, the package contained no install scripts, instead hiding its loader inside a standard library method that triggered only when called with a specific argument. Once activated, the malware collected system details such as hostname, CPU, and memory, then transmitted them to hardcoded Slack and Telegram channels. It used a smart contract on the Ethereum Sepolia testnet to dynamically retrieve its command-and-control server address, making it resilient to domain or IP blocking. The malware also fetched an encrypted second-stage payload via the same smart contract using X25519 key exchange and AES decryption, though the contents of that payload have not been publicly disclosed.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in