CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Six npm Packages Read C2 Addresses From Ethereum Wallet

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5992

As cited

Copy frozen at (site build).

Six npm Packages Read C2 Addresses From Ethereum Wallet

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Six npm Packages Read C2 Addresses From Ethereum Wallet

Six npm packages contained code that queried an Ethereum wallet to retrieve command and control (C2) infrastructure addresses. The packages used blockchain lookups as an obfuscation technique to hide malicious server locations from detection.

Why it matters: Software developers and dependency managers need to audit npm packages for hidden C2 communications, as compromised packages can execute arbitrary commands on systems where they are installed.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary