← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 10, 2026 · 16:10via Malware.news

Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads

Brief

TL;DR

  • Sonatype Research Labs identified six npm packages delivering the same malicious payload: three hijacked legitimate packages and three additional malicious packages, tracked as sonatype-2026-005899 and sonatype-2026-005901 .
  • The malware uses the same Ethereum wallet address identified by OpenSourceMalware in activity attributed to the DPRK-linked Contagious Interview campaign, using the "NullReceiver" technique to locate infrastructure hosting additional JavaScript payloads.
  • Organizations that installed the affected versions should remove them and investigate the impacted environment for follow-on payload execution or compromise.

On August 10, 2026, Sonatype Research Labs identified six npm packages containing the same malicious payload, including three compromised legitimate packages and three packages published with the malware already present.

Read more on Malware.news