ZeroHour
Infosecurity Magazinepublished ()ingested

Six npm Packages Read C2 Addresses From Ethereum Wallet

mediumMalware exploited in the wildimportance 45
AI summary · glm-5.3

Six malicious npm packages query an Ethereum wallet to resolve C2 addresses, hiding command-and-control infrastructure.

Six malicious packages on the npm registry were found querying an Ethereum wallet to locate their command-and-control infrastructure. Storing C2 addresses on the blockchain lets operators rotate infrastructure while avoiding hard-coded servers that are easy to block or sinkhole. The campaign targets developers installing dependencies from npm.

  • Six npm packages pull C2 addresses from an Ethereum wallet
  • Blockchain-based C2 removes hard-coded infrastructure from malware
  • Supply-chain threat to developers installing npm packages
Full article

Six npm packages queried an Ethereum wallet to locate C2 infrastructure

This source does not provide full text. Read it at infosecurity-magazine.com.