Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads
Brief
TL;DR
- Sonatype Research Labs identified six npm packages delivering the same malicious payload: three hijacked legitimate packages and three additional malicious packages, tracked as sonatype-2026-005899 and sonatype-2026-005901 .
- The malware uses the same Ethereum wallet address identified by OpenSourceMalware in activity attributed to the DPRK-linked Contagious Interview campaign, using the "NullReceiver" technique to locate infrastructure hosting additional JavaScript payloads.
- Organizations that installed the affected versions should remove them and investigate the impacted environment for follow-on payload execution or compromise.
On August 10, 2026, Sonatype Research Labs identified six npm packages containing the same malicious payload, including three compromised legitimate packages and three packages published with the malware already present.
