Six npm Packages Read C2 Addresses From Ethereum Wallet
Six malicious npm packages query an Ethereum wallet to resolve C2 addresses, hiding command-and-control infrastructure.
Six malicious packages on the npm registry were found querying an Ethereum wallet to locate their command-and-control infrastructure. Storing C2 addresses on the blockchain lets operators rotate infrastructure while avoiding hard-coded servers that are easy to block or sinkhole. The campaign targets developers installing dependencies from npm.