As cited
Copy frozen at (site build).
Six npm Packages Read C2 Addresses From Ethereum Wallet
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Six npm Packages Read C2 Addresses From Ethereum Wallet
Six npm packages contained code that queried an Ethereum wallet to retrieve command and control (C2) infrastructure addresses. The packages used blockchain lookups as an obfuscation technique to hide malicious server locations from detection.
Why it matters: Software developers and dependency managers need to audit npm packages for hidden C2 communications, as compromised packages can execute arbitrary commands on systems where they are installed.
- Source published
- First seen by Cybersecurity Tracker